CVE-2022-3697High· 7.5▾ TwilightAnsible leaks password to logs
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
0.7% → 0.8%
A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.
ansible >= 2.5.0, < 7.0.0Upgrade to a patched release:
ansible 7.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2023-5115Medium· 6.3Ansible symlink attack vulnerability
CVE-2021-20180Medium· 5.5Insertion of Sensitive Information into Log File in ansible
CVE-2025-14010Medium· 5.5Ansible Community General Collection is vulnerable to exposure of sensitive information