AWS Security Advisories · October 2023 — AWS Security Advisories
41 advisories 76 CVEs 6 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2023-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 6 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2023-1869

ALAS · AL1ExploitedCISA KEV listedImportant2023-10-17

ALAS-2023-1869: nghttp2 (important)

CVEs:CVE-2023-44487

Affected products

ProductStatusVendorPackageEcosystem
nghttp2 affected Amazon nghttp2
Upstream advisory

ALAS-2023-1870

ALAS · AL1ExploitedCISA KEV listedImportant2023-10-17

ALAS-2023-1870: nginx (important)

CVEs:CVE-2023-44487

Affected products

ProductStatusVendorPackageEcosystem
nginx affected Amazon nginx
Upstream advisory

ALAS-2023-1872

ALAS · AL1Active exploitation (sightings)Critical2023-10-28

ALAS-2023-1872: squid (critical)

CVEs:CVE-2023-46847

Affected products

ProductStatusVendorPackageEcosystem
squid affected Amazon squid
Upstream advisory

ALAS-2023-1854

ALAS · AL1Active exploitation (sightings)Medium2023-10-03

ALAS-2023-1854: ghostscript (medium)

CVEs:CVE-2020-16305

Affected products

ProductStatusVendorPackageEcosystem
ghostscript affected Amazon ghostscript
Upstream advisory

ALAS-2023-1842

ALAS · AL1Active exploitation (sightings)Important2023-10-03

ALAS-2023-1842: cacti (important)

CVEs:CVE-2023-39357

Affected products

ProductStatusVendorPackageEcosystem
cacti affected Amazon cacti
Upstream advisory

ALAS-2023-1856

ALAS · AL1PoC exploitMedium2023-10-24

ALAS-2023-1856: ImageMagick (medium)

CVEs:CVE-2023-5341

Affected products

ProductStatusVendorPackageEcosystem
ImageMagick affected Amazon ImageMagick
Upstream advisory

ALAS-2023-1845

ALAS · AL1Coalition ESS < 30%Important2023-10-03

ALAS-2023-1845: bind (important)

CVEs:CVE-2023-3341

Affected products

ProductStatusVendorPackageEcosystem
bind affected Amazon bind
Upstream advisory

ALAS-2023-1863

ALAS · AL1Coalition ESS < 30%Important2023-10-24

ALAS-2023-1863: apache-ivy (important)

CVEs:CVE-2022-46751

Affected products

ProductStatusVendorPackageEcosystem
apache-ivy affected Amazon apache-ivy
Upstream advisory

ALAS-2023-1846

ALAS · AL1Coalition ESS < 30%Medium2023-10-03

ALAS-2023-1846: libtiff (medium)

CVEs:CVE-2023-3316

Affected products

ProductStatusVendorPackageEcosystem
libtiff affected Amazon libtiff
Upstream advisory

ALAS-2023-1844

ALAS · AL1Coalition ESS < 30%Medium2023-10-03

ALAS-2023-1844: ImageMagick (medium)

CVEs:CVE-2023-34151

Affected products

ProductStatusVendorPackageEcosystem
ImageMagick affected Amazon ImageMagick
Upstream advisory

ALAS-2023-1858

ALAS · AL1Coalition ESS < 30%Medium2023-10-24

ALAS-2023-1858: nss-softokn (medium)

CVEs:CVE-2023-4421

Affected products

ProductStatusVendorPackageEcosystem
nss-softokn affected Amazon nss-softokn
Upstream advisory

ALAS-2023-1867

ALAS · AL1EPSS <= 49%Medium2023-10-24

ALAS-2023-1867: ghostscript (medium)

CVEs:CVE-2020-16294

Affected products

ProductStatusVendorPackageEcosystem
ghostscript affected Amazon ghostscript
Upstream advisory

ALAS-2023-1853

ALAS · AL1EPSS <= 49%Medium2023-10-03

ALAS-2023-1853: ghostscript (medium)

CVEs:CVE-2020-21710

Affected products

ProductStatusVendorPackageEcosystem
ghostscript affected Amazon ghostscript
Upstream advisory

ALAS-2023-1864

ALAS · AL1EPSS <= 49%Important2023-10-24

ALAS-2023-1864: java-1.8.0-openjdk (important)

CVEs:CVE-2022-40433

Affected products

ProductStatusVendorPackageEcosystem
java-1.8.0-openjdk affected Amazon java-1.8.0-openjdk
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.