AWS Security Advisories · June 2020 — AWS Security Advisories
23 advisories 106 CVEs

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2020-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2020-1389

ALAS · AL1Weaponized exploitImportant2020-06-26

ALAS-2020-1389: tomcat7 (important)

CVEs:CVE-2020-9484

Affected products

ProductStatusVendorPackageEcosystem
tomcat7 affected Amazon tomcat7
Upstream advisory

ALAS-2020-1390

ALAS · AL1Weaponized exploitImportant2020-06-26

ALAS-2020-1390: tomcat8 (important)

CVEs:CVE-2020-9484

Affected products

ProductStatusVendorPackageEcosystem
tomcat8 affected Amazon tomcat8
Upstream advisory

ALAS-2020-1391

ALAS · AL1Active exploitation (sightings)Medium2020-06-26

ALAS-2020-1391: php-pecl-imagick (medium)

CVEs:CVE-2017-1000476CVE-2017-11166CVE-2017-12805CVE-2017-12806CVE-2017-18251CVE-2017-18252CVE-2017-18254CVE-2017-18271CVE-2017-18273CVE-2018-10177CVE-2018-10804CVE-2018-10805CVE-2018-11656CVE-2018-12599CVE-2018-12600CVE-2018-13153CVE-2018-14434CVE-2018-14435CVE-2018-14436CVE-2018-14437CVE-2018-15607CVE-2018-16328CVE-2018-16749CVE-2018-16750CVE-2018-18544CVE-2018-20467CVE-2018-8804CVE-2018-9133CVE-2019-10131CVE-2019-10650CVE-2019-11470CVE-2019-11472CVE-2019-11597CVE-2019-11598CVE-2019-12974CVE-2019-12975CVE-2019-12976CVE-2019-12978CVE-2019-12979CVE-2019-13133CVE-2019-13134CVE-2019-13135CVE-2019-13295CVE-2019-13297CVE-2019-13300CVE-2019-13301CVE-2019-13304CVE-2019-13305CVE-2019-13306CVE-2019-13307CVE-2019-13309CVE-2019-13310CVE-2019-13311CVE-2019-13454CVE-2019-14980CVE-2019-14981CVE-2019-15139CVE-2019-15140CVE-2019-15141CVE-2019-16708CVE-2019-16709CVE-2019-16710CVE-2019-16711CVE-2019-16712CVE-2019-16713CVE-2019-17540CVE-2019-17541CVE-2019-19948CVE-2019-19949CVE-2019-7175CVE-2019-7397CVE-2019-7398CVE-2019-9956

Affected products

ProductStatusVendorPackageEcosystem
php-pecl-imagick affected Amazon php-pecl-imagick
Upstream advisory

ALAS-2020-1380

ALAS · AL1Active exploitation (sightings)Important2020-06-26

ALAS-2020-1380: exim (important)

CVEs:CVE-2020-12783

Affected products

ProductStatusVendorPackageEcosystem
exim affected Amazon exim
Upstream advisory

ALAS-2020-1384

ALAS · AL1PoC exploitMedium2020-06-26

ALAS-2020-1384: rubygem-rake (medium)

CVEs:CVE-2020-8130

Affected products

ProductStatusVendorPackageEcosystem
rubygem-rake affected Amazon rubygem-rake
Upstream advisory

ALAS-2020-1385

ALAS · AL1PoC exploitMedium2020-06-26

ALAS-2020-1385: rubygem24-rake (medium)

CVEs:CVE-2020-8130

Affected products

ProductStatusVendorPackageEcosystem
rubygem24-rake affected Amazon rubygem24-rake
Upstream advisory

ALAS-2020-1372

ALAS · AL1EPSS <= 49%Important2020-06-03

ALAS-2020-1372: python-twisted-web (important)

CVEs:CVE-2020-10108

Affected products

ProductStatusVendorPackageEcosystem
python-twisted-web affected Amazon python-twisted-web
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.