Vulnerability Description
A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ansible | >= 2.5.0, < 2.10.0 |
| Redhat | Ansible Collection | < 2.0.0 |
Related Weaknesses (CWE)
References
- https://github.com/ansible-collections/amazon.aws/pull/1199Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html
- https://github.com/ansible-collections/amazon.aws/pull/1199Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html
FAQ
What is CVE-2022-3697?
CVE-2022-3697 is a vulnerability with a CVSS score of 7.5 (HIGH). A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue a...
How severe is CVE-2022-3697?
CVE-2022-3697 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-3697?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Ansible, Redhat Ansible Collection.