Ansible leaks password to logs
High severity
GitHub Reviewed
Published
Oct 28, 2022
to the GitHub Advisory Database
•
Updated Jan 6, 2024
Description
Published by the National Vulnerability Database
Oct 28, 2022
Published to the GitHub Advisory Database
Oct 28, 2022
Reviewed
Jan 24, 2023
Last updated
Jan 6, 2024
A flaw was found in Ansible in the amazon.aws collection when using the
tower_callback
parameter from theamazon.aws.ec2_instance
module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.References