A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.
References
| Link | Resource |
|---|---|
| https://github.com/ansible-collections/amazon.aws/pull/1199 | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2022-10-28 16:15
Updated : 2023-12-28 19:15
NVD link : CVE-2022-3697
Mitre link : CVE-2022-3697
CVE.ORG link : CVE-2022-3697
JSON object : View
Products Affected
redhat
- ansible
- ansible_collection
CWE
