AWS Security Advisories · July 2017 — AWS Security Advisories
9 advisories 25 CVEs

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2017-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2017-861

ALAS · AL1Weaponized exploitImportant2017-07-25

ALAS-2017-861: aws-cfn-bootstrap (important)

CVEs:CVE-2017-9450

Affected products

ProductStatusVendorPackageEcosystem
aws-cfn-bootstrap affected Amazon aws-cfn-bootstrap
Upstream advisory

ALAS-2017-856

ALAS · AL1PoC exploitImportant2017-07-06

ALAS-2017-856: mercurial (important)

CVEs:CVE-2017-9462

Affected products

ProductStatusVendorPackageEcosystem
mercurial affected Amazon mercurial
Upstream advisory

ALAS-2017-854

ALAS · AL1EPSS <= 49%Important2017-07-06

ALAS-2017-854: tomcat8 (important)

CVEs:CVE-2017-5664

Affected products

ProductStatusVendorPackageEcosystem
tomcat8 affected Amazon tomcat8
Upstream advisory

ALAS-2017-853

ALAS · AL1EPSS <= 49%Important2017-07-06

ALAS-2017-853: tomcat7 (important)

CVEs:CVE-2017-5664

Affected products

ProductStatusVendorPackageEcosystem
tomcat7 affected Amazon tomcat7
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.