Vulnerabilities > Amazon

DATE CVE VULNERABILITY TITLE RISK
2022-11-11 CVE-2022-41906 Unspecified vulnerability in Amazon Opensearch Notifications
OpenSearch Notifications is a notifications plugin for OpenSearch that enables other plugins to send notifications via Email, Slack, Amazon Chime, Custom web-hook etc channels.
network
low complexity
amazon
8.7
2022-09-29 CVE-2022-41828 Incorrect Type Conversion or Cast vulnerability in Amazon web Services Redshift Java Database Connectivity Driver
In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name.
network
high complexity
amazon CWE-704
8.1
2022-09-23 CVE-2022-39230 Unspecified vulnerability in Amazon Fhir-Works-On-Aws-Authz-Smart 3.1.0/3.1.1/3.1.2
fhir-works-on-aws-authz-smart is an implementation of the authorization interface from the FHIR Works interface.
network
low complexity
amazon
6.5
2022-08-12 CVE-2022-35980 Unspecified vulnerability in Amazon Opensearch 2.0.0/2.1.0
OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization.
network
low complexity
amazon
7.5
2022-07-15 CVE-2022-31159 Unspecified vulnerability in Amazon Aws-Sdk-Java
The AWS SDK for Java enables Java developers to work with Amazon Web Services.
network
low complexity
amazon
6.5
2022-06-30 CVE-2022-31115 Unspecified vulnerability in Amazon Opensearch 1.0.0/2.0.0/2.0.1
opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby.
network
low complexity
amazon
8.8
2022-06-17 CVE-2022-33915 Race Condition vulnerability in Amazon Hotpatch 1.112/1.116
Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.3.5 are affected by a race condition that could lead to a local privilege escalation.
local
high complexity
amazon CWE-362
7.0
2022-04-20 CVE-2022-29527 Incorrect Permission Assignment for Critical Resource vulnerability in Amazon SSM Agent
Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate privileges to root.
local
high complexity
amazon CWE-732
7.0
2022-04-19 CVE-2021-3100 Improper Privilege Management vulnerability in Amazon Log4Jhotpatch
The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges.
local
low complexity
amazon CWE-269
8.8
2022-04-19 CVE-2022-0070 Improper Privilege Management vulnerability in Amazon Log4Jhotpatch
Incomplete fix for CVE-2021-3100.
local
low complexity
amazon CWE-269
8.8