AWS Security Advisories · December 2018 — AWS Security Advisories
24 advisories 69 CVEs 1 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2018-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2018-1137

ALAS · AL1ExploitedCISA KEV listedImportant2018-12-20

ALAS-2018-1137: ghostscript (important)

CVEs:CVE-2018-16509

Affected products

ProductStatusVendorPackageEcosystem
ghostscript affected Amazon ghostscript
Upstream advisory

ALAS-2018-1132

ALAS · AL1PoC exploitMedium2018-12-20

ALAS-2018-1132: python34, python36 (medium)

CVEs:CVE-2018-14647

Affected products

ProductStatusVendorPackageEcosystem
python34, python36 affected Amazon python34, python36
Upstream advisory

ALAS-2018-1117

ALAS · AL1PoC exploitImportant2018-12-06

ALAS-2018-1117: postgresql93, postgresql94 (important)

CVEs:CVE-2018-10915

Affected products

ProductStatusVendorPackageEcosystem
postgresql93, postgresql94 affected Amazon postgresql93, postgresql94
Upstream advisory

ALAS-2018-1106

ALAS · AL1EPSS <= 49%Medium2018-12-06

ALAS-2018-1106: 389-ds-base (medium)

CVEs:CVE-2018-14648

Affected products

ProductStatusVendorPackageEcosystem
389-ds-base affected Amazon 389-ds-base
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.