AWS Security Advisories · March 2018 — AWS Security Advisories
16 advisories 67 CVEs 1 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2018-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

Advisories

ALAS-2018-978

ALAS · AL1Medium2018-03-21

ALAS-2018-978: ruby24, ruby22, ruby23 (medium)

CVEs:CVE-2017-0903

Affected products

ProductStatusVendorPackageEcosystem
ruby24, ruby22, ruby23 affected Amazon ruby24, ruby22, ruby23
Upstream advisory

ALAS-2018-977

ALAS · AL1Medium2018-03-21

ALAS-2018-977: python-crypto (medium)

CVEs:CVE-2018-6594

Affected products

ProductStatusVendorPackageEcosystem
python-crypto affected Amazon python-crypto
Upstream advisory

ALAS-2018-968

ALAS · AL1Medium2018-03-07

ALAS-2018-968: mod_auth_mellon, mod24_auth_mellon (medium)

CVEs:CVE-2017-6807

Affected products

ProductStatusVendorPackageEcosystem
mod_auth_mellon, mod24_auth_mellon affected Amazon mod_auth_mellon, mod24_auth_mellon
Upstream advisory

ALAS-2018-965

ALAS · AL1Medium2018-03-07

ALAS-2018-965: tomcat-native (medium)

CVEs:CVE-2017-15698

Affected products

ProductStatusVendorPackageEcosystem
tomcat-native affected Amazon tomcat-native
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.