AWS Security Advisories · August 2023 — AWS Security Advisories
23 advisories 45 CVEs 1 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2023-08. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2023-1802

ALAS · AL1ExploitedVulnCheck KEV listedImportant2023-08-22

ALAS-2023-1802: openssh (important)

CVEs:CVE-2023-38408

Affected products

ProductStatusVendorPackageEcosystem
openssh affected Amazon openssh
Upstream advisory

ALAS-2023-1791

ALAS · AL1Active exploitation (sightings)Medium2023-08-08

ALAS-2023-1791: ImageMagick (medium)

CVEs:CVE-2023-3745

Affected products

ProductStatusVendorPackageEcosystem
ImageMagick affected Amazon ImageMagick
Upstream advisory

ALAS-2023-1798

ALAS · AL1PoC exploitImportant2023-08-08

ALAS-2023-1798: java-1.8.0-openjdk (important)

CVEs:CVE-2023-21930

Affected products

ProductStatusVendorPackageEcosystem
java-1.8.0-openjdk affected Amazon java-1.8.0-openjdk
Upstream advisory

ALAS-2023-1799

ALAS · AL1Coalition ESS < 30%Important2023-08-08

ALAS-2023-1799: GraphicsMagick (important)

CVEs:CVE-2022-1270

Affected products

ProductStatusVendorPackageEcosystem
GraphicsMagick affected Amazon GraphicsMagick
Upstream advisory

ALAS-2023-1801

ALAS · AL1Coalition ESS < 30%Medium2023-08-22

ALAS-2023-1801: ghostscript (medium)

CVEs:CVE-2023-38559

Affected products

ProductStatusVendorPackageEcosystem
ghostscript affected Amazon ghostscript
Upstream advisory

ALAS-2023-1795

ALAS · AL1All remainingImportant2023-08-08

ALAS-2023-1795: ca-certificates (important)

CVEs:CVE-2023-32803

Affected products

ProductStatusVendorPackageEcosystem
ca-certificates affected Amazon ca-certificates
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.