AWS Security Advisories · December 2021 — AWS Security Advisories
6 advisories 5 CVEs 3 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2021-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 3 are already weaponised in the wild — see the Exploited section.

Advisories

ALAS-2021-1554

ALAS · AL1Important2021-12-23

ALAS-2021-1554: log4j-cve-2021-44228-hotpatch (important)

CVEs:CVE-2021-3100

Affected products

ProductStatusVendorPackageEcosystem
log4j-cve-2021-44228-hotpatch affected Amazon log4j-cve-2021-44228-hotpatch
Upstream advisory

ALAS-2021-1553

ALAS · AL1ExploitedCritical2021-12-18

ALAS-2021-1553: java-1.8.0-openjdk, java-1.7.0-openjdk, java-1.6.0-openjdk (critical)

CVEs:CVE-2021-44228CVE-2021-45046

Affected products

ProductStatusVendorPackageEcosystem
java-1.8.0-openjdk, java-1.7.0-openjdk, java-1.6.0-openjdk affected Amazon java-1.8.0-openjdk, java-1.7.0-openjdk, java-1.6.0-openjdk
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.