HIGH
ansible: improper handling of tower_callback parameter in amazon.aws collection
Published Oct 28, 2022
7.5
HIGHCVSS 3.1
EPSS 0.78%
Description
A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.
Affected products
- Vendor n/a Product Ansible, Ansible Community.aws, Ansible Amazon.aws Defaultn/a
- Version ansible amazon.aws from 2.1.0 before 5.1.0StatusaffectedConstraints-
- Version ansible community.aws before 2.0.0StatusaffectedConstraints-
- Version ansible from 2.5.0 before 2.10StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | Ansible, Ansible Community.aws, Ansible Amazon.aws | n/a |
|
OR
- ≥ 2.5.0 · < 2.10.0
- < 2.0.0
- ≥ 2.1.0 · < 5.1.0
No data.
Red Hat Ansible Automation Platform 2
ansible-automation-platform-25/ee-supported-rhel8
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-25/ee-supported-rhel8 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- https://access.redhat.com/security/cve/CVE-2022-3697 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2137664 Issue Tracking
- https://github.com/advisories/GHSA-cpx3-93w7-457x Advisory
- https://github.com/ansible-collections/amazon.aws/pull/1199 Third Party Advisory
- https://github.com/ansible-community/ansible-build-data/blob/main/6/CHANGELOG-v6.rst
- https://github.com/ansible/ansible/pull/35749
- https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html
- https://nvd.nist.gov/vuln/detail/CVE-2022-3697
- https://www.cve.org/CVERecord?id=CVE-2022-3697
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 28, 2022
Updated Feb 13, 2025
Reserved Oct 26, 2022
Link CVE-2022-3697
CISA Vulnrichment
GHSA-CPX3-93W7-457X Updated n/a