A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.
https://github.com/advisories/GHSA-cpx3-93w7-457x
https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html