AWS Security Advisories · August 2020 — AWS Security Advisories
16 advisories 25 CVEs

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2020-08. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2020-1421

ALAS · AL1Weaponized exploitMedium2020-08-31

ALAS-2020-1421: python-rsa (medium)

CVEs:CVE-2020-13757

Affected products

ProductStatusVendorPackageEcosystem
python-rsa affected Amazon python-rsa
Upstream advisory

ALAS-2020-1425

ALAS · AL1Active exploitation (sightings)Low2020-08-31

ALAS-2020-1425: php72, php73 (low)

CVEs:CVE-2020-7068

Affected products

ProductStatusVendorPackageEcosystem
php72, php73 affected Amazon php72, php73
Upstream advisory

ALAS-2020-1423

ALAS · AL1PoC exploitMedium2020-08-31

ALAS-2020-1423: rubygem-json (medium)

CVEs:CVE-2020-10663

Affected products

ProductStatusVendorPackageEcosystem
rubygem-json affected Amazon rubygem-json
Upstream advisory

ALAS-2020-1426

ALAS · AL1PoC exploitMedium2020-08-31

ALAS-2020-1426: ruby19, ruby21 (medium)

CVEs:CVE-2020-10663

Affected products

ProductStatusVendorPackageEcosystem
ruby19, ruby21 affected Amazon ruby19, ruby21
Upstream advisory

ALAS-2020-1420

ALAS · AL1EPSS <= 49%Medium2020-08-31

ALAS-2020-1420: python-httplib2 (medium)

CVEs:CVE-2020-11078

Affected products

ProductStatusVendorPackageEcosystem
python-httplib2 affected Amazon python-httplib2
Upstream advisory

ALAS-2020-1414

ALAS · AL1EPSS <= 49%Medium2020-08-12

ALAS-2020-1414: keepalived (medium)

CVEs:CVE-2018-19044

Affected products

ProductStatusVendorPackageEcosystem
keepalived affected Amazon keepalived
Upstream advisory

ALAS-2020-1418

ALAS · AL1All remainingLow2020-08-31

ALAS-2020-1418: httpd24 (low)

Affected products

ProductStatusVendorPackageEcosystem
httpd24 affected Amazon httpd24
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.