AWS-2021-007
AWSSupportServiceRolePolicy Informational Update
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 3 are already weaponised in the wild — see the Exploited section.
AWSSupportServiceRolePolicy Informational Update
ALAS-2021-1554: log4j-cve-2021-44228-hotpatch (important)
CVEs:CVE-2021-3100
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| log4j-cve-2021-44228-hotpatch | affected | Amazon | log4j-cve-2021-44228-hotpatch | — |
ALAS-2021-1553: java-1.8.0-openjdk, java-1.7.0-openjdk, java-1.6.0-openjdk (critical)
CVEs:CVE-2021-44228CVE-2021-45046
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| java-1.8.0-openjdk, java-1.7.0-openjdk, java-1.6.0-openjdk | affected | Amazon | java-1.8.0-openjdk, java-1.7.0-openjdk, java-1.6.0-openjdk | — |
Update for Apache Log4j2 Issue (CVE-2021-44228)
Apache Log4j2 Issue (CVE-2021-44228)
CVEs:CVE-2021-44228
ALAS-2021-1552: nss (critical)
CVEs:CVE-2021-43527
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| nss | affected | Amazon | nss | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.