CVE Database
/

CVE-2022-3697

Back to search

CVE-2022-3697

Published: Oct 28, 2022

Modified: Feb 13, 2025

PUBLISHED

Description

A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.

VendorProductVersions

n/a

ansible, ansible community.aws, ansible amazon.aws

affected
ansible from 2.5.0 before 2.10
affected
ansible community.aws before 2.0.0
affected
ansible amazon.aws from 2.1.0 before 5.1.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now