AWS Security Advisories · January 2023 — AWS Security Advisories
19 advisories 13 CVEs 1 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2023-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2023-1675

ALAS · AL1ExploitedCISA KEV listedCritical2023-01-24

ALAS-2023-1675: cacti (critical)

CVEs:CVE-2022-46169

Affected products

ProductStatusVendorPackageEcosystem
cacti affected Amazon cacti
Upstream advisory

ALAS-2023-1662

ALAS · AL1Active exploitation (sightings)Important2023-01-24

ALAS-2023-1662: exim (important)

CVEs:CVE-2022-3559

Affected products

ProductStatusVendorPackageEcosystem
exim affected Amazon exim
Upstream advisory

ALAS-2023-1657

ALAS · AL1PoC exploitMedium2023-01-24

ALAS-2023-1657: postgresql92 (medium)

CVEs:CVE-2021-23214

Affected products

ProductStatusVendorPackageEcosystem
postgresql92 affected Amazon postgresql92
Upstream advisory

ALAS-2023-1658

ALAS · AL1PoC exploitMedium2023-01-24

ALAS-2023-1658: postgresql93 (medium)

CVEs:CVE-2021-23214

Affected products

ProductStatusVendorPackageEcosystem
postgresql93 affected Amazon postgresql93
Upstream advisory

ALAS-2023-1659

ALAS · AL1PoC exploitMedium2023-01-24

ALAS-2023-1659: postgresql94 (medium)

CVEs:CVE-2021-23214

Affected products

ProductStatusVendorPackageEcosystem
postgresql94 affected Amazon postgresql94
Upstream advisory

ALAS-2023-1660

ALAS · AL1PoC exploitMedium2023-01-24

ALAS-2023-1660: postgresql95 (medium)

CVEs:CVE-2021-23214

Affected products

ProductStatusVendorPackageEcosystem
postgresql95 affected Amazon postgresql95
Upstream advisory

ALAS-2023-1661

ALAS · AL1PoC exploitMedium2023-01-24

ALAS-2023-1661: postgresql96 (medium)

CVEs:CVE-2021-23214

Affected products

ProductStatusVendorPackageEcosystem
postgresql96 affected Amazon postgresql96
Upstream advisory

ALAS-2023-1669

ALAS · AL1Coalition ESS < 30%Critical2023-01-24

ALAS-2023-1669: php-pecl-memcached (critical)

CVEs:CVE-2022-26635

Affected products

ProductStatusVendorPackageEcosystem
php-pecl-memcached affected Amazon php-pecl-memcached
Upstream advisory

ALAS-2023-1670

ALAS · AL1Coalition ESS < 30%Critical2023-01-24

ALAS-2023-1670: php54-pecl-memcached (critical)

CVEs:CVE-2022-26635

Affected products

ProductStatusVendorPackageEcosystem
php54-pecl-memcached affected Amazon php54-pecl-memcached
Upstream advisory

ALAS-2023-1671

ALAS · AL1Coalition ESS < 30%Critical2023-01-24

ALAS-2023-1671: php55-pecl-memcached (critical)

CVEs:CVE-2022-26635

Affected products

ProductStatusVendorPackageEcosystem
php55-pecl-memcached affected Amazon php55-pecl-memcached
Upstream advisory

ALAS-2023-1672

ALAS · AL1Coalition ESS < 30%Critical2023-01-24

ALAS-2023-1672: php56-pecl-memcached (critical)

CVEs:CVE-2022-26635

Affected products

ProductStatusVendorPackageEcosystem
php56-pecl-memcached affected Amazon php56-pecl-memcached
Upstream advisory

ALAS-2023-1673

ALAS · AL1Coalition ESS < 30%Critical2023-01-24

ALAS-2023-1673: php70-pecl-memcached (critical)

CVEs:CVE-2022-26635

Affected products

ProductStatusVendorPackageEcosystem
php70-pecl-memcached affected Amazon php70-pecl-memcached
Upstream advisory

ALAS-2023-1674

ALAS · AL1Coalition ESS < 30%Critical2023-01-24

ALAS-2023-1674: php71-pecl-memcached (critical)

CVEs:CVE-2022-26635

Affected products

ProductStatusVendorPackageEcosystem
php71-pecl-memcached affected Amazon php71-pecl-memcached
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.