Alibaba Security Advisories · December 2024 — Alibaba Security Advisories
10 advisories 12 CVEs 1 EXPLOITED

Alibaba Cloud Linux 2 advisories and cross-source Alibaba/Aliyun CVEs for 2024-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

Advisories

ALINUX2-SA-2024:0041

ALINUX 22024-12-02

ALINUX2-SA-2024:0041: python-setuptools security update (Important)

CVEs:CVE-2024-6345

Affected products

ProductStatusVendorPackageEcosystem
python-setuptools affected Alibaba Cloud python-setuptools
Upstream advisory

ALINUX2-SA-2024:0042

ALINUX 22024-12-02

ALINUX2-SA-2024:0042: NetworkManager-libreswan security update (Important)

CVEs:CVE-2024-9050

Affected products

ProductStatusVendorPackageEcosystem
NetworkManager-libreswan affected Alibaba Cloud NetworkManager-libreswan
Upstream advisory

ALINUX2-SA-2024:0043

ALINUX 22024-12-02

ALINUX2-SA-2024:0043: python3-setuptools security update (Important)

CVEs:CVE-2024-6345

Affected products

ProductStatusVendorPackageEcosystem
python3-setuptools affected Alibaba Cloud python3-setuptools
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.