A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3695-1 | ansible security update |
Github GHSA |
GHSA-cpx3-93w7-457x | Ansible leaks password to logs |
Ubuntu USN |
USN-6846-1 | Ansible vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-02-13T16:32:52.283Z
Reserved: 2022-10-26T00:00:00.000Z
Link: CVE-2022-3697
No data.
Status : Modified
Published: 2022-10-28T16:15:16.403
Modified: 2024-11-21T07:20:03.293
Link: CVE-2022-3697
OpenCVE Enrichment
No data.
Debian DLA
Github GHSA
Ubuntu USN