AWS-2023-008
Kubernetes Security Issues (CVE-2023-3676, CVE-2023-3893, CVE-2023-3955)
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.
Kubernetes Security Issues (CVE-2023-3676, CVE-2023-3893, CVE-2023-3955)
ALAS-2023-1801: ghostscript (medium)
CVEs:CVE-2023-38559
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ghostscript | affected | Amazon | ghostscript | — |
ALAS-2023-1802: openssh (important)
CVEs:CVE-2023-38408
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| openssh | affected | Amazon | openssh | — |
ALAS-2023-1803: kernel (medium)
CVEs:CVE-2023-34319CVE-2023-4128
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kernel | affected | Amazon | kernel | — |
ALAS-2023-1804: openldap (medium)
CVEs:CVE-2023-2953
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| openldap | affected | Amazon | openldap | — |
ALAS-2023-1805: monit (important)
CVEs:CVE-2022-26563
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| monit | affected | Amazon | monit | — |
ALAS-2023-1806: GraphicsMagick (important)
CVEs:CVE-2020-21679CVE-2022-1270
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| GraphicsMagick | affected | Amazon | GraphicsMagick | — |
ALAS-2023-1807: transfig (medium)
CVEs:CVE-2019-19797CVE-2020-21678CVE-2020-21681CVE-2020-21682CVE-2020-21683CVE-2020-21684CVE-2021-32280
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| transfig | affected | Amazon | transfig | — |
ALAS-2023-1808: amanda (medium)
CVEs:CVE-2016-10729CVE-2023-30577
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| amanda | affected | Amazon | amanda | — |
CVE-2022-40982 - Gather Data Sampling - Downfall
CVEs:CVE-2022-40982
CVE-2023-20569 - RAS Poisoning - Inception
CVEs:CVE-2023-20569
ALAS-2023-1790: avahi (medium)
CVEs:CVE-2023-38469CVE-2023-38470CVE-2023-38471
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| avahi | affected | Amazon | avahi | — |
ALAS-2023-1791: ImageMagick (medium)
CVEs:CVE-2023-3745
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ImageMagick | affected | Amazon | ImageMagick | — |
ALAS-2023-1792: kernel (important)
CVEs:CVE-2023-3609CVE-2023-3611CVE-2023-3776
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kernel | affected | Amazon | kernel | — |
ALAS-2023-1793: nghttp2 (important)
CVEs:CVE-2023-35945
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| nghttp2 | affected | Amazon | nghttp2 | — |
ALAS-2023-1794: openssh (medium)
CVEs:CVE-2023-35812
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| openssh | affected | Amazon | openssh | — |
ALAS-2023-1795: ca-certificates (important)
CVEs:CVE-2023-32803
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ca-certificates | affected | Amazon | ca-certificates | — |
ALAS-2023-1796: cups (medium)
CVEs:CVE-2023-32324
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| cups | affected | Amazon | cups | — |
ALAS-2023-1797: java-1.8.0-openjdk (medium)
CVEs:CVE-2023-21937CVE-2023-21938CVE-2023-21939CVE-2023-21954CVE-2023-21967CVE-2023-21968CVE-2023-22043CVE-2023-22045CVE-2023-22049
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| java-1.8.0-openjdk | affected | Amazon | java-1.8.0-openjdk | — |
ALAS-2023-1798: java-1.8.0-openjdk (important)
CVEs:CVE-2023-21930
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| java-1.8.0-openjdk | affected | Amazon | java-1.8.0-openjdk | — |
ALAS-2023-1799: GraphicsMagick (important)
CVEs:CVE-2022-1270
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| GraphicsMagick | affected | Amazon | GraphicsMagick | — |
ALAS-2023-1800: python-ecdsa (important)
CVEs:CVE-2019-14853CVE-2019-14859
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| python-ecdsa | affected | Amazon | python-ecdsa | — |
Recent Software-based Power Side-Channel Security Research
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.