Alibaba Security Advisories · March 2020 — Alibaba Security Advisories
13 advisories 25 CVEs 1 EXPLOITED

Alibaba Cloud Linux 2 advisories and cross-source Alibaba/Aliyun CVEs for 2020-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALINUX2-SA-2020:0032

ALINUX 2ExploitedCISA KEV listed2020-03-20

ALINUX2-SA-2020:0032: tomcat security update (Important)

CVEs:CVE-2020-1938

Affected products

ProductStatusVendorPackageEcosystem
tomcat affected Alibaba Cloud tomcat
Upstream advisory

ALINUX2-SA-2020:0027

ALINUX 2Active exploitation (sightings)2020-03-05

ALINUX2-SA-2020:0027: xerces-c security update (Important)

CVEs:CVE-2018-1311

Affected products

ProductStatusVendorPackageEcosystem
xerces-c affected Alibaba Cloud xerces-c
Upstream advisory

ALINUX2-SA-2020:0034

ALINUX 2Active exploitation (sightings)2020-03-26

ALINUX2-SA-2020:0034: libvncserver security update (Important)

CVEs:CVE-2019-15690

Affected products

ProductStatusVendorPackageEcosystem
libvncserver affected Alibaba Cloud libvncserver
Upstream advisory

ALINUX2-SA-2020:0026

ALINUX 2PoC exploit2020-03-05

ALINUX2-SA-2020:0026: http-parser security update (Important)

CVEs:CVE-2019-15605

Affected products

ProductStatusVendorPackageEcosystem
http-parser affected Alibaba Cloud http-parser
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.