Tag: AWS
Kubernetes Security Issues (CVE-2023-3676, CVE-2023-3893, CVE-2023-3893)
Publication Date: 2023/08/23 10:00 AM PDT
AWS is aware of three security issues (CVE-2023-3676, CVE-2023-3893, CVE-2023-3893) in Kubernetes that affect Amazon EKS customers with Windows EC2 nodes in their clusters. These issues do not affect any Kubernetes control...
CVE-2022-40982 – Gather Data Sampling – Downfall
Publication Date: 2023/08/08 1:00 PM PDT
AWS is aware of CVE-2022-40982, also known as “Gather Data Sampling” (GDS) or “Downfall”. AWS customers’ data and instances are not affected by this issue, and no customer action is required. AWS...
CVE-2023-20569 – RAS Poisoning – Inception
Publication Date: 2023/08/08 11:30AM PDT
AWS is aware of CVE-2023-20569, also known as “RAS Poisoning” or “Inception”. AWS customers’ data and instances are not affected by this issue, and no customer action is required. AWS has designed and...
Recent Software-based Power Side-Channel Security Research
Publication Date: 2023/08/01 10:00AM PDT
AWS is aware of recently-published security research describing software-based power side-channel concerns, otherwise known as ”Collide+Power“. AWS customers’ data and instances are not impacted by this issue, and no customer action is required....
CVE-2023-20593
Initial Publication Date: 07/26/2023 11:00AM PDT
AWS is aware of CVE-2023-20593, otherwise known as "ZenBleed", and can confirm this issue affects AMD “Zen 2”, also known as “Rome”, CPUs that power the C5a, C5ad, G4ad, and G5 instance families....
Issue with AWS Directory Service EnableRoleAccess
Initial Publication Date: 06/14/2023 4:30PM PDT
A researcher recently reported an issue in AWS Directory Service which would have enabled customer’s IAM principals, who are allowed to call the “EnableRoleAccess” API, to enable role access on the directory user...
Reported GuardDuty Finding Issue
Initial Publication Date: 05/18/2023 10:00AM EST
A security researcher recently reported an issue in Amazon GuardDuty in which a change to the policy of an S3 bucket not protected by Block Public Access (BPA) could be carried out to...
Issue With IAM Supporting Multiple MFA Devices
Initial Publication Date: 04/25/2023 10:00AM EST
A security researcher recently reported an issue with AWS’s recently-released (November 16th, 2022) support for multiple multi-factor authentication (MFA) devices for IAM user principals. The reported issue could have potentially arisen only when...
Reported ECR Public Gallery Issue
Initial Publication Date: 12/13/2022 9:00AM EST
On November 14, 2022, a security researcher reported an issue in Amazon Elastic Container Registry (ECR) Public Gallery, a public website for finding and sharing public container images. The researcher identified an...
Reported AWS AppSync Issue
Initial Publication Date: 2022/11/21 10:00AM EST
A security researcher recently disclosed a case-sensitivity parsing issue within AWS AppSync, which could potentially be used to bypass the service’s cross-account role usage validations and take action as the service across...
OpenSSL Security Advisories – November 2022
Initial Publication Date: 2022/11/01 09:00 PDT
AWS is aware of the recently reported issues regarding OpenSSL 3.0 (CVE-2022-3602 and CVE-2022-3786). AWS services are not affected, and no customer action is required. Additionally, Amazon Linux 1 and Amazon Linux...