Alibaba Security Advisories · March 2021 — Alibaba Security Advisories
7 advisories 11 CVEs 1 EXPLOITED

Alibaba Cloud Linux 2 advisories and cross-source Alibaba/Aliyun CVEs for 2021-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALINUX2-SA-2021:0015

ALINUX 2ExploitedCISA KEV listedMEDIUM2021-03-18

ALINUX2-SA-2021:0015: ipa security and bug fix update (Moderate)

CVEs:CVE-2020-11023

Affected products

ProductStatusVendorPackageEcosystem
ipa affected Alibaba Cloud ipa
Upstream advisory

ALINUX2-SA-2021:0016

ALINUX 2Coalition ESS < 30%HIGH2021-03-30

ALINUX2-SA-2021:0016: flatpak security update (Important)

CVEs:CVE-2021-21381

Affected products

ProductStatusVendorPackageEcosystem
flatpak affected Alibaba Cloud flatpak
Upstream advisory

ALINUX2-SA-2021:0013

ALINUX 2Coalition ESS < 30%HIGH2021-03-11

ALINUX2-SA-2021:0013: wpa_supplicant security update (Important)

CVEs:CVE-2021-27803

Affected products

ProductStatusVendorPackageEcosystem
wpa_supplicant affected Alibaba Cloud wpa_supplicant
Upstream advisory

HOTFIX-BA-2021:0003

ALINUX 2All remaining2021-03-18

HOTFIX-BA-2021:0003: kernel-hotfix bugfix update (Important)

Affected products

ProductStatusVendorPackageEcosystem
kernel-hotfix-5000697-21.al7 affected Alibaba Cloud kernel-hotfix-5000697-21.al7
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.