CVE-2022-3697
28.10.2022, 16:15
A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.Enginsight
| Vendor | Product | Version |
|---|---|---|
| redhat | ansible | 2.5.0 ≤ 𝑥 < 2.10.0 |
| redhat | ansible_collection | 𝑥 < 2.0.0 |
| redhat | ansible_collection | 2.1.0 ≤ 𝑥 < 5.1.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ansible |
| ||||||||||||||||||
| ansible-core |
|
Common Weakness Enumeration