<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:13:46 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-00283</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00283</link>
      <description>bdu:2022-00283</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00283</guid>
    </item>
    <item>
      <title>BREW-ansible-CVE-2020-1735</title>
      <link>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2020-1735</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-ansible-cve-2020-1735</guid>
    </item>
    <item>
      <title>cnvd-2020-10514</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-10514</link>
      <description>cnvd-2020-10514</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-10514</guid>
    </item>
    <item>
      <title>EUVD-2026-35579</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-35579</link>
      <description>EUVD-2026-35579</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-35579</guid>
    </item>
    <item>
      <title>fkie_cve-2020-1735</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-1735</link>
      <description>&lt;p&gt;A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-1735</guid>
    </item>
    <item>
      <title>GHSA-gfr2-qpxh-qj9m — Path Traversal in Ansible</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gfr2-qpxh-qj9m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gfr2-qpxh-qj9m</guid>
    </item>
    <item>
      <title>gsd-2020-1735</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-1735</link>
      <description>gsd-2020-1735</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-1735</guid>
    </item>
    <item>
      <title>OESA-2021-1349 — ansible security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1349</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP2: ansible&lt;/p&gt;
&lt;p&gt;Ansible is a radically simple model-driven configuration management, multi-node deployment, and remote task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument &amp;amp;quot;password&amp;amp;quot; of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.(CVE-2020-1739)&#13;
&#13;
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes &amp;amp;quot;ansible-vault edit&amp;amp;quot;, another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing secret in the file. This method will delete the file before recreating it insecurely. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.(CVE-2020-1740)&#13;
&#13;
A flaw was found in Ansible Engine when the module package or service is used and the parameter &amp;amp;apos;use&amp;amp;apos; is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP2: ansible&lt;/p&gt;
&lt;p&gt;Ansible is a radically simple model-driven configuration management, multi-node deployment, and remote task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument &amp;amp;quot;password&amp;amp;quot; of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.(CVE-2020-1739)&#13;
&#13;
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes &amp;amp;quot;ansible-vault edit&amp;amp;quot;, another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing secret in the file. This method will delete the file before recreating it insecurely. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.(CVE-2020-1740)&#13;
&#13;
A flaw was found in Ansible Engine when the module package or service is used and the parameter &amp;amp;apos;use&amp;amp;apos; is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1349</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:0081-1 — Security update for ansible</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0081-1</link>
      <description>&lt;p&gt;Security update for ansible&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ansible&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:0081-1</guid>
    </item>
    <item>
      <title>PYSEC-2020-7</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2020-7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2020-7</guid>
    </item>
    <item>
      <title>RHBA-2020:0547 — Red Hat Bug Fix Advisory: Container Image Rebuild for Ansible Tower 3.4 Dependency</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2020:0547</link>
      <description>&lt;p&gt;glibc: getaddrinfo should reject IP addresses with trailing characters ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries openssl: timing side channel attack in the DSA signature algorithm procps: Local privilege escalation in top LibRaw: DoS in parse_rollei function in internal/dcraw_common.cpp LibRaw: DoS in parse_sinar_ia function in internal/dcraw_common.cpp nss: Cache side-channel variant of the Bleichenbacher attack binutils: Stack Exhaustion in the demangling functions provided by libiberty binutils: NULL pointer dereference in work_stuff_copy_to_from in cplus-dem.c. curl: NTLM password overflow via integer overflow python: Missing salt initialization in _elementtree.c module systemd: line splitting via fgets() allows for state injection during daemon-reexec elfutils: Heap-based buffer over-read in libdw/dwarf_getaranges.c:dwarf_getaranges() via crafted file elfutils: Double-free due to double decompression of sections in crafted ELF causes crash elfutils: Heap-based buffer over-read in libdw/dwarf_getabbrev.c and libwd/dwarf_hasattr.c causes crash curl: Heap-based buffer over-read in the curl tool warning formatting systemd: out-of-bounds read when parsing a crafted syslog message systemd: kills privileged process if unprivileged PIDFile was tampered elfutils: invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl elfutils: eu-size cannot handle recursive ar files elfutils: Divide-by-zero in arlib_add_symbols functio…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;glibc: getaddrinfo should reject IP addresses with trailing characters ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries openssl: timing side channel attack in the DSA signature algorithm procps: Local privilege escalation in top LibRaw: DoS in parse_rollei function in internal/dcraw_common.cpp LibRaw: DoS in parse_sinar_ia function in internal/dcraw_common.cpp nss: Cache side-channel variant of the Bleichenbacher attack binutils: Stack Exhaustion in the demangling functions provided by libiberty binutils: NULL pointer dereference in work_stuff_copy_to_from in cplus-dem.c. curl: NTLM password overflow via integer overflow python: Missing salt initialization in _elementtree.c module systemd: line splitting via fgets() allows for state injection during daemon-reexec elfutils: Heap-based buffer over-read in libdw/dwarf_getaranges.c:dwarf_getaranges() via crafted file elfutils: Double-free due to double decompression of sections in crafted ELF causes crash elfutils: Heap-based buffer over-read in libdw/dwarf_getabbrev.c and libwd/dwarf_hasattr.c causes crash curl: Heap-based buffer over-read in the curl tool warning formatting systemd: out-of-bounds read when parsing a crafted syslog message systemd: kills privileged process if unprivileged PIDFile was tampered elfutils: invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl elfutils: eu-size cannot handle recursive ar files elfutils: Divide-by-zero in arlib_add_symbols functio…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2020:0547</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-1735</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-1735</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ansible, Ubuntu:Pro:16.04:LTS: ansible, Ubuntu:Pro:18.04:LTS: ansible, Ubuntu:Pro:20.04:LTS: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ansible, Ubuntu:Pro:16.04:LTS: ansible, Ubuntu:Pro:18.04:LTS: ansible, Ubuntu:Pro:20.04:LTS: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-1735</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2478 — Ansible: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2478</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Ansible ausnutzen, um Sicherheitsvorkehrungen zu umgehen und Informationen offenzulegen&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Ansible ausnutzen, um Sicherheitsvorkehrungen zu umgehen und Informationen offenzulegen&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2478</guid>
    </item>
  </channel>
</rss>
