AWS Security Advisories · January 2024 — AWS Security Advisories
13 advisories 26 CVEs 2 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2024-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2024-1905

ALAS · AL1ExploitedCISA KEV listedImportant2024-01-22

ALAS-2024-1905: perl-Spreadsheet-ParseExcel (important)

CVEs:CVE-2023-7101

Affected products

ProductStatusVendorPackageEcosystem
perl-Spreadsheet-ParseExcel affected Amazon perl-Spreadsheet-ParseExcel
Upstream advisory

ALAS-2024-1901

ALAS · AL1Active exploitation (sightings)Important2024-01-09

ALAS-2024-1901: squid (important)

CVEs:CVE-2023-49285

Affected products

ProductStatusVendorPackageEcosystem
squid affected Amazon squid
Upstream advisory

ALAS-2024-1908

ALAS · AL1Active exploitation (sightings)Important2024-01-22

ALAS-2024-1908: exim (important)

CVEs:CVE-2023-51766

Affected products

ProductStatusVendorPackageEcosystem
exim affected Amazon exim
Upstream advisory

ALAS-2024-1907

ALAS · AL1PoC exploitMedium2024-01-22

ALAS-2024-1907: nss-softokn (medium)

CVEs:CVE-2023-5388

Affected products

ProductStatusVendorPackageEcosystem
nss-softokn affected Amazon nss-softokn
Upstream advisory

ALAS-2024-1910

ALAS · AL1Coalition ESS < 30%Important2024-01-22

ALAS-2024-1910: apache-ivy (important)

CVEs:CVE-2022-37866

Affected products

ProductStatusVendorPackageEcosystem
apache-ivy affected Amazon apache-ivy
Upstream advisory

ALAS-2024-1906

ALAS · AL1Coalition ESS < 30%Important2024-01-22

ALAS-2024-1906: kernel (important)

CVEs:CVE-2023-6606

Affected products

ProductStatusVendorPackageEcosystem
kernel affected Amazon kernel
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.