CVE-2022-3697: A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs. Maintainers, are we vulnerable here? Not sure how ansible-collections patches make their way into our package.
Fixed in https://github.com/ansible-collections/amazon.aws/commit/5fe427c6f4152489b2ed7f8ede86eb9b65940922 first released in amazon.aws 6.0.0. First fixed version in gentoo is 8.3.0 (7.7.0 still contains amazon.aws 5.x).