<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 03:39:22 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-06980</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-06980</link>
      <description>bdu:2024-06980</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-06980</guid>
    </item>
    <item>
      <title>BREW-ansible-CVE-2021-20191</title>
      <link>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2021-20191</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-ansible-cve-2021-20191</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-XW66953 — flaw was found in ansible</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-xw66953</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ansible&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the ansible package. A flaw was found in ansible.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ansible&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the ansible package. A flaw was found in ansible.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-xw66953</guid>
    </item>
    <item>
      <title>cnvd-2021-19700</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-19700</link>
      <description>cnvd-2021-19700</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-19700</guid>
    </item>
    <item>
      <title>EUVD-2026-21509</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-21509</link>
      <description>EUVD-2026-21509</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-21509</guid>
    </item>
    <item>
      <title>fkie_cve-2021-20191</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-20191</link>
      <description>&lt;p&gt;A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-20191</guid>
    </item>
    <item>
      <title>GHSA-8f4m-hccc-8qph — Insertion of Sensitive Information into Log File in ansible</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8f4m-hccc-8qph</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8f4m-hccc-8qph</guid>
    </item>
    <item>
      <title>gsd-2021-20191</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-20191</link>
      <description>gsd-2021-20191</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-20191</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-20191 — A flaw was found in ansible. Credentials such as secrets are being disclosed in console log by default and not protecte…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-20191</link>
      <description>msrc_CVE-2021-20191</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-20191</guid>
    </item>
    <item>
      <title>OESA-2021-1349 — ansible security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1349</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP2: ansible&lt;/p&gt;
&lt;p&gt;Ansible is a radically simple model-driven configuration management, multi-node deployment, and remote task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument &amp;amp;quot;password&amp;amp;quot; of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.(CVE-2020-1739)&#13;
&#13;
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes &amp;amp;quot;ansible-vault edit&amp;amp;quot;, another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing secret in the file. This method will delete the file before recreating it insecurely. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.(CVE-2020-1740)&#13;
&#13;
A flaw was found in Ansible Engine when the module package or service is used and the parameter &amp;amp;apos;use&amp;amp;apos; is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP2: ansible&lt;/p&gt;
&lt;p&gt;Ansible is a radically simple model-driven configuration management, multi-node deployment, and remote task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument &amp;amp;quot;password&amp;amp;quot; of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.(CVE-2020-1739)&#13;
&#13;
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes &amp;amp;quot;ansible-vault edit&amp;amp;quot;, another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing secret in the file. This method will delete the file before recreating it insecurely. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.(CVE-2020-1740)&#13;
&#13;
A flaw was found in Ansible Engine when the module package or service is used and the parameter &amp;amp;apos;use&amp;amp;apos; is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1349</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:0081-1 — Security update for ansible</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0081-1</link>
      <description>&lt;p&gt;Security update for ansible&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ansible&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:0081-1</guid>
    </item>
    <item>
      <title>PYSEC-2021-124</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2021-124</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2021-124</guid>
    </item>
    <item>
      <title>RHSA-2021:0663 — Red Hat Security Advisory: Ansible security and bug fix update (2.9.18)</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:0663</link>
      <description>&lt;p&gt;ansible: user data leak in snmp_facts module module: bitbucket_pipeline_variable exposes secured values ansible: multiple modules expose secured values ansible: basic.py no_log with fallback option&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ansible: user data leak in snmp_facts module module: bitbucket_pipeline_variable exposes secured values ansible: multiple modules expose secured values ansible: basic.py no_log with fallback option&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:0663</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:2121-1 — Security update for ansible</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:2121-1</link>
      <description>&lt;p&gt;Security update for ansible&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ansible&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:2121-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-20191</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-20191</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ansible, Ubuntu:Pro:16.04:LTS: ansible, Ubuntu:Pro:18.04:LTS: ansible, Ubuntu:Pro:20.04:LTS: ansible, Ubuntu:Pro:22.04:LTS: ansible, Ubuntu:24.04:LTS: ansible, Ubuntu:25.10: ansible, Ubuntu:26.04:LTS: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ansible, Ubuntu:Pro:16.04:LTS: ansible, Ubuntu:Pro:18.04:LTS: ansible, Ubuntu:Pro:20.04:LTS: ansible, Ubuntu:Pro:22.04:LTS: ansible, Ubuntu:24.04:LTS: ansible, Ubuntu:25.10: ansible, Ubuntu:26.04:LTS: ansible&lt;/p&gt;
&lt;p&gt;A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-20191</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1350 — Ansible: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1350</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Ansible ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Ansible ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1350</guid>
    </item>
  </channel>
</rss>
