A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.
References
| Link | Resource |
|---|---|
| https://github.com/ansible-collections/amazon.aws/pull/1199 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-10-28 09:15
Updated : 2022-11-01 11:47
NVD link : CVE-2022-3697
Mitre link : CVE-2022-3697
JSON object : View
CWE
Products Affected
redhat
- ansible_collection
- ansible


