Alibaba Security Advisories · January 2020 — Alibaba Security Advisories
14 advisories 22 CVEs 1 EXPLOITED

Alibaba Cloud Linux 2 advisories and cross-source Alibaba/Aliyun CVEs for 2020-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

Advisories

ALINUX2-SA-2020:0010

ALINUX 22020-01-31

ALINUX2-SA-2020:0010: python-reportlab security update (Important)

CVEs:CVE-2019-17626

Affected products

ProductStatusVendorPackageEcosystem
python-reportlab affected Alibaba Cloud python-reportlab
Upstream advisory

ALINUX2-SA-2020:0005

ALINUX 22020-01-03

ALINUX2-SA-2020:0005: nss, nss-softokn, nss-util security update (Important)

CVEs:CVE-2019-11729CVE-2019-11745

Affected products

ProductStatusVendorPackageEcosystem
nss affected Alibaba Cloud nss
nss-softokn affected Alibaba Cloud nss-softokn
nss-util affected Alibaba Cloud nss-util
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.