<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:31:00 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-00282</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00282</link>
      <description>bdu:2022-00282</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00282</guid>
    </item>
    <item>
      <title>BREW-ansible-CVE-2020-1733</title>
      <link>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2020-1733</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with &amp;#34;umask 77 &amp;amp;&amp;amp; mkdir -p &amp;lt;dir&amp;gt;&amp;#34;; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating &amp;#39;/proc/&amp;lt;pid&amp;gt;/cmdline&amp;#39;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with &amp;#34;umask 77 &amp;amp;&amp;amp; mkdir -p &amp;lt;dir&amp;gt;&amp;#34;; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating &amp;#39;/proc/&amp;lt;pid&amp;gt;/cmdline&amp;#39;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-ansible-cve-2020-1733</guid>
    </item>
    <item>
      <title>cnvd-2020-19559</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-19559</link>
      <description>cnvd-2020-19559</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-19559</guid>
    </item>
    <item>
      <title>EUVD-2026-35582</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-35582</link>
      <description>EUVD-2026-35582</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-35582</guid>
    </item>
    <item>
      <title>fkie_cve-2020-1733</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-1733</link>
      <description>&lt;p&gt;A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with &amp;#34;umask 77 &amp;amp;&amp;amp; mkdir -p &amp;lt;dir&amp;gt;&amp;#34;; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating &amp;#39;/proc/&amp;lt;pid&amp;gt;/cmdline&amp;#39;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with &amp;#34;umask 77 &amp;amp;&amp;amp; mkdir -p &amp;lt;dir&amp;gt;&amp;#34;; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating &amp;#39;/proc/&amp;lt;pid&amp;gt;/cmdline&amp;#39;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-1733</guid>
    </item>
    <item>
      <title>GHSA-g4mq-6fp5-qwcf — Ansible vulnerable to Exposure of Resource to Wrong Sphere and Insecure Temporary File</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g4mq-6fp5-qwcf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with &amp;#34;umask 77 &amp;amp;&amp;amp; mkdir -p &amp;lt;dir&amp;gt;&amp;#34;; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating &amp;#39;/proc/&amp;lt;pid&amp;gt;/cmdline&amp;#39;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with &amp;#34;umask 77 &amp;amp;&amp;amp; mkdir -p &amp;lt;dir&amp;gt;&amp;#34;; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating &amp;#39;/proc/&amp;lt;pid&amp;gt;/cmdline&amp;#39;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g4mq-6fp5-qwcf</guid>
    </item>
    <item>
      <title>gsd-2020-1733</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-1733</link>
      <description>gsd-2020-1733</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-1733</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:0081-1 — Security update for ansible</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0081-1</link>
      <description>&lt;p&gt;Security update for ansible&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ansible&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:0081-1</guid>
    </item>
    <item>
      <title>PYSEC-2020-5</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2020-5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with &amp;#34;umask 77 &amp;amp;&amp;amp; mkdir -p &amp;lt;dir&amp;gt;&amp;#34;; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating &amp;#39;/proc/&amp;lt;pid&amp;gt;/cmdline&amp;#39;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with &amp;#34;umask 77 &amp;amp;&amp;amp; mkdir -p &amp;lt;dir&amp;gt;&amp;#34;; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating &amp;#39;/proc/&amp;lt;pid&amp;gt;/cmdline&amp;#39;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2020-5</guid>
    </item>
    <item>
      <title>RHSA-2020:1541 — Red Hat Security Advisory: Ansible security and bug fix update (2.9.7)</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:1541</link>
      <description>&lt;p&gt;ansible: insecure temporary directory when running become_user from become directive ansible: path injection on dest parameter in fetch module ansible: Extract-Zip function in win_unzip module does not check extracted path ansible: svn module leaks password when specified as a parameter ansible: secrets readable after ansible-vault edit ansible: Information disclosure issue in ldap_attr and ldap_entry modules Ansible: kubectl connection plugin leaks sensitive information Ansible: code injection when using ansible_facts as a subkey Ansible: modules which use files encrypted with vault are not properly cleaned up Ansible: archive traversal vulnerability in ansible-galaxy collection install&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ansible: insecure temporary directory when running become_user from become directive ansible: path injection on dest parameter in fetch module ansible: Extract-Zip function in win_unzip module does not check extracted path ansible: svn module leaks password when specified as a parameter ansible: secrets readable after ansible-vault edit ansible: Information disclosure issue in ldap_attr and ldap_entry modules Ansible: kubectl connection plugin leaks sensitive information Ansible: code injection when using ansible_facts as a subkey Ansible: modules which use files encrypted with vault are not properly cleaned up Ansible: archive traversal vulnerability in ansible-galaxy collection install&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:1541</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-1733</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-1733</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ansible, Ubuntu:Pro:18.04:LTS: ansible, Ubuntu:Pro:20.04:LTS: ansible&lt;/p&gt;
&lt;p&gt;A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with &amp;#34;umask 77 &amp;amp;&amp;amp; mkdir -p &amp;lt;dir&amp;gt;&amp;#34;; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating &amp;#39;/proc/&amp;lt;pid&amp;gt;/cmdline&amp;#39;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ansible, Ubuntu:Pro:18.04:LTS: ansible, Ubuntu:Pro:20.04:LTS: ansible&lt;/p&gt;
&lt;p&gt;A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with &amp;#34;umask 77 &amp;amp;&amp;amp; mkdir -p &amp;lt;dir&amp;gt;&amp;#34;; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating &amp;#39;/proc/&amp;lt;pid&amp;gt;/cmdline&amp;#39;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-1733</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2479 — Ansible: Schwachstelle ermöglicht Unsicheres Erzeugen von temporären Dateien</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2479</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Ansible ausnutzen, um temporäre Dateien zu erzeugen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Ansible ausnutzen, um temporäre Dateien zu erzeugen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2479</guid>
    </item>
  </channel>
</rss>
