AWS Security Advisories · March 2023 — AWS Security Advisories
15 advisories 62 CVEs 1 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2023-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2023-1698

ALAS · AL1PoC exploitImportant2023-03-07

ALAS-2023-1698: cifs-utils (important)

CVEs:CVE-2022-27239

Affected products

ProductStatusVendorPackageEcosystem
cifs-utils affected Amazon cifs-utils
Upstream advisory

ALAS-2023-1705

ALAS · AL1Coalition ESS < 30%Important2023-03-20

ALAS-2023-1705: lighttpd (important)

CVEs:CVE-2022-37797

Affected products

ProductStatusVendorPackageEcosystem
lighttpd affected Amazon lighttpd
Upstream advisory

ALAS-2023-1699

ALAS · AL1Coalition ESS < 30%Medium2023-03-07

ALAS-2023-1699: freeradius (medium)

CVEs:CVE-2022-41860

Affected products

ProductStatusVendorPackageEcosystem
freeradius affected Amazon freeradius
Upstream advisory

ALAS-2023-1702

ALAS · AL1Coalition ESS < 30%Important2023-03-20

ALAS-2023-1702: xorg-x11-server (important)

CVEs:CVE-2023-0494

Affected products

ProductStatusVendorPackageEcosystem
xorg-x11-server affected Amazon xorg-x11-server
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.