AWS Security Advisories · June 2023 — AWS Security Advisories
30 advisories 47 CVEs 2 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2023-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2023-1750

ALAS · AL1ExploitedVulnCheck KEV listedImportant2023-06-06

ALAS-2023-1750: kernel (important)

CVEs:CVE-2023-32233

Affected products

ProductStatusVendorPackageEcosystem
kernel affected Amazon kernel
Upstream advisory

ALAS-2023-1771

ALAS · AL1PoC exploitImportant2023-06-27

ALAS-2023-1771: perl-HTTP-Tiny (important)

CVEs:CVE-2023-31486

Affected products

ProductStatusVendorPackageEcosystem
perl-HTTP-Tiny affected Amazon perl-HTTP-Tiny
Upstream advisory

ALAS-2023-1759

ALAS · AL1PoC exploitImportant2023-06-08

ALAS-2023-1759: postgresql92 (important)

CVEs:CVE-2023-2454

Affected products

ProductStatusVendorPackageEcosystem
postgresql92 affected Amazon postgresql92
Upstream advisory

ALAS-2023-1772

ALAS · AL1PoC exploitMedium2023-06-27

ALAS-2023-1772: mod24_security (medium)

CVEs:CVE-2022-48279

Affected products

ProductStatusVendorPackageEcosystem
mod24_security affected Amazon mod24_security
Upstream advisory

ALAS-2023-1763

ALAS · AL1PoC exploitMedium2023-06-08

ALAS-2023-1763: mod_security (medium)

CVEs:CVE-2022-48279

Affected products

ProductStatusVendorPackageEcosystem
mod_security affected Amazon mod_security
Upstream advisory

ALAS-2023-1764

ALAS · AL1Coalition ESS < 30%Medium2023-06-08

ALAS-2023-1764: freetype (medium)

CVEs:CVE-2022-27406

Affected products

ProductStatusVendorPackageEcosystem
freetype affected Amazon freetype
Upstream advisory

ALAS-2023-1752

ALAS · AL1Coalition ESS < 30%Important2023-06-06

ALAS-2023-1752: libksba (important)

CVEs:CVE-2022-47629

Affected products

ProductStatusVendorPackageEcosystem
libksba affected Amazon libksba
Upstream advisory

ALAS-2023-1765

ALAS · AL1Coalition ESS < 30%Medium2023-06-08

ALAS-2023-1765: mod24_auth_mellon (medium)

CVEs:CVE-2021-3639

Affected products

ProductStatusVendorPackageEcosystem
mod24_auth_mellon affected Amazon mod24_auth_mellon
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.