CVE-2022-3697
published 2022-10-28CVE-2022-3697: A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.71%
49.5th percentile
A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 7.0.0+dfsg-1 (bookworm) | ansible 7.0.0+dfsg-1 (bookworm) |
| msrc | cm1_ansible_2.9.27-2_on_cbl_mariner_1.0 | — | — |
| redhat | ansible | >= 0 < 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1 | 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1 |
| redhat | ansible | >= 0 < 7.0.0+dfsg-1 | 7.0.0+dfsg-1 |
| redhat | ansible | >= 0 < 7.0.0+dfsg-1 | 7.0.0+dfsg-1 |
| redhat | ansible | >= 0 < 7.0.0+dfsg-1 | 7.0.0+dfsg-1 |
| redhat | ansible | >= 0 < 2.0.0.2-2ubuntu1.3+esm2 | 2.0.0.2-2ubuntu1.3+esm2 |
| redhat | ansible | >= 0 < 2.0.0.2-2ubuntu1.3+esm3 | 2.0.0.2-2ubuntu1.3+esm3 |
| redhat | ansible | >= 0 < 2.5.1+dfsg-1ubuntu0.1+esm2 | 2.5.1+dfsg-1ubuntu0.1+esm2 |
| redhat | ansible | >= 0 < 2.5.1+dfsg-1ubuntu0.1+esm3 | 2.5.1+dfsg-1ubuntu0.1+esm3 |
| redhat | ansible | >= 0 < 2.9.6+dfsg-1ubuntu0.1~esm2 | 2.9.6+dfsg-1ubuntu0.1~esm2 |
| redhat | ansible | >= 0 < 2.10.7+merged+base+2.10.8+dfsg-1ubuntu0.1~esm4 | 2.10.7+merged+base+2.10.8+dfsg-1ubuntu0.1~esm4 |
| redhat | ansible | >= 2.5.0 < 2.10.0 | 2.10.0 |
| redhat | ansible | >= 2.5.0 < 7.0.0 | 7.0.0 |
| redhat | ansible_collection | < 2.0.0 | 2.0.0 |
| redhat | ansible_collection | >= 2.1.0 < 5.1.0 | 5.1.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ansible regression
osv·2024-12-02·CVSS 7.5
[HIGH] ansible regression
ansible regression
USN-6846-1 fixed vulnerabilities in ansible. The update introduced a
regression in ansible. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Ansible incorrectly handled certain inputs when
using tower_callback parameter. If a user or an automated system were
tricked into opening a specially crafted input file, a remote attacker
could possibly use this issue to obtain sensitive information. This issue
only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2022-3697)
It was discovered that Ansible incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to perform
OSV
ansible vulnerabilities
osv·2024-06-25·CVSS 7.5
CVE-2022-3697 [HIGH] ansible vulnerabilities
ansible vulnerabilities
It was discovered that Ansible incorrectly handled certain inputs when using
tower_callback parameter. If a user or an automated system were tricked into
opening a specially crafted input file, a remote attacker could possibly use
this issue to obtain sensitive information. This issue only affected Ubuntu
18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-3697)
It was discovered that Ansible incorrectly handled certain inputs. If a user or
an automated system were tricked into opening a specially crafted input file, a
remote attacker could possibly use this issue to perform a Template Injection.
(CVE-2023-5764)
GHSA
Ansible leaks password to logs
ghsa·2022-10-28
CVE-2022-3697 [HIGH] CWE-233 Ansible leaks password to logs
Ansible leaks password to logs
A flaw was found in Ansible in the amazon.aws collection when using the `tower_callback` parameter from the `amazon.aws.ec2_instance` module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.
OSV
Ansible leaks password to logs
osv·2022-10-28
CVE-2022-3697 [HIGH] Ansible leaks password to logs
Ansible leaks password to logs
A flaw was found in Ansible in the amazon.aws collection when using the `tower_callback` parameter from the `amazon.aws.ec2_instance` module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.
OSV
CVE-2022-3697: A flaw was found in Ansible in the amazon
osv·2022-10-28·CVSS 7.5
CVE-2022-3697 [HIGH] CVE-2022-3697: A flaw was found in Ansible in the amazon
A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.
Ubuntu
Ansible regression
vendor_ubuntu·2025-02-13·CVSS 7.5
[HIGH] Ansible regression
Title: Ansible regression
Summary: USN-6846-2 caused some regression in ansible.
USN-6846-1 fixed vulnerabilities in ansible. The update introduced a
regression in ansible. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Ansible incorrectly handled certain inputs when
using tower_callback parameter. If a user or an automated system were
tricked into opening a specially crafted input file, a remote attacker
could possibly use this issue to obtain sensitive information. This issue
only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2022-3697)
It was discovered that Ansible incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input f
Ubuntu
Ansible regression
vendor_ubuntu·2024-12-02·CVSS 7.5
[HIGH] Ansible regression
Title: Ansible regression
Summary: USN-6846-1 caused some regression in ansible.
USN-6846-1 fixed vulnerabilities in ansible. The update introduced a
regression in ansible. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Ansible incorrectly handled certain inputs when
using tower_callback parameter. If a user or an automated system were
tricked into opening a specially crafted input file, a remote attacker
could possibly use this issue to obtain sensitive information. This issue
only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2022-3697)
It was discovered that Ansible incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input f
Ubuntu
Ansible vulnerabilities
vendor_ubuntu·2024-06-25·CVSS 7.5
CVE-2023-5764 [HIGH] Ansible vulnerabilities
Title: Ansible vulnerabilities
Summary: Several security issues were fixed in Ansible.
It was discovered that Ansible incorrectly handled certain inputs when using
tower_callback parameter. If a user or an automated system were tricked into
opening a specially crafted input file, a remote attacker could possibly use
this issue to obtain sensitive information. This issue only affected Ubuntu
18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-3697)
It was discovered that Ansible incorrectly handled certain inputs. If a user or
an automated system were tricked into opening a specially crafted input file, a
remote attacker could possibly use this issue to perform a Template Injection.
(CVE-2023-5764)
Instructions: In general, a standard system update will make all the necessary c
Red Hat
ansible: improper handling of tower_callback parameter in amazon.aws collection
vendor_redhat·2022-10-25·CVSS 7.5
CVE-2022-3697 [HIGH] CWE-233 ansible: improper handling of tower_callback parameter in amazon.aws collection
ansible: improper handling of tower_callback parameter in amazon.aws collection
A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.
A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.
Package: ansible-automation-platform-25/ee-supported-rhel8 (Red Hat Ansible Automation Platform 2) - Will not fix
Microsoft
A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue a
vendor_msrc·2022-10-11·CVSS 7.5
CVE-2022-3697 [HIGH] CWE-233 A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue a
A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blo
Debian
CVE-2022-3697: ansible - A flaw was found in Ansible in the amazon.aws collection when using the tower_ca...
vendor_debian·2022·CVSS 7.5
CVE-2022-3697 [HIGH] CVE-2022-3697: ansible - A flaw was found in Ansible in the amazon.aws collection when using the tower_ca...
A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.
Scope: local
bookworm: resolved (fixed in 7.0.0+dfsg-1)
bullseye: resolved (fixed in 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1)
forky: resolved (fixed in 7.0.0+dfsg-1)
sid: resolved (fixed in 7.0.0+dfsg-1)
trixie: resolved (fixed in 7.0.0+dfsg-1)
No detection rules found.
No public exploits indexed.
2022-10-28
Published