« Volver al listado

CVE-2022-3697

Estado: ModificadaAlta (7.5)—

A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-3697",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "ansible, ansible community.aws, ansible amazon.aws",
          "versions": [
            {
              "status": "affected",
              "version": "ansible from 2.5.0 before 2.10"
            },
            {
              "status": "affected",
              "version": "ansible community.aws before 2.0.0"
            },
            {
              "status": "affected",
              "version": "ansible amazon.aws from 2.1.0 before 5.1.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-10-28T16:15:16.403",
  "references": [
    {
      "url": "https://github.com/ansible-collections/amazon.aws/pull/1199",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://github.com/ansible-collections/amazon.aws/pull/1199",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-233"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs."
    },
    {
      "lang": "es",
      "value": "Se encontró una falla en Ansible en la colección amazon.aws al usar el parámetro tower_callback del módulo amazon.aws.ec2_instance. Esta falla permite que un atacante aproveche este problema ya que el módulo maneja el parámetro de manera insegura, lo que provoca que la contraseña se filtre en los registros."
    }
  ],
  "lastModified": "2026-06-17T05:00:07.890",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9DBC8935-27B7-4048-92C9-942D24D116A0",
              "versionEndExcluding": "2.10.0",
              "versionStartIncluding": "2.5.0"
            },
            {
              "criteria": "cpe:2.3:a:redhat:ansible_collection:*:*:*:*:*:community_aws:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2549F857-19D5-4359-BCE4-2DAB72D52F5B",
              "versionEndExcluding": "2.0.0"
            },
            {
              "criteria": "cpe:2.3:a:redhat:ansible_collection:*:*:*:*:*:aws:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D8990581-F433-4EB1-96B8-383A4342D6F7",
              "versionEndExcluding": "5.1.0",
              "versionStartIncluding": "2.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}