Vulnerabilities > Amazon > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-03 | CVE-2023-1385 | Use of Insufficiently Random Values vulnerability in Amazon Fire OS Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthorized authentication to amzn.lightning services. This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS 7.6.3.3. | 8.8 |
2023-01-26 | CVE-2023-23612 | Improper Authentication vulnerability in Amazon Opensearch OpenSearch is an open source distributed and RESTful search engine. | 8.8 |
2022-11-11 | CVE-2022-41906 | Server-Side Request Forgery (SSRF) vulnerability in Amazon Opensearch Notifications OpenSearch Notifications is a notifications plugin for OpenSearch that enables other plugins to send notifications via Email, Slack, Amazon Chime, Custom web-hook etc channels. | 8.7 |
2022-09-29 | CVE-2022-41828 | Incorrect Type Conversion or Cast vulnerability in Amazon web Services Redshift Java Database Connectivity Driver In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name. | 8.1 |
2022-08-12 | CVE-2022-35980 | Unspecified vulnerability in Amazon Opensearch 2.0.0/2.1.0 OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. | 7.5 |
2022-06-30 | CVE-2022-31115 | Deserialization of Untrusted Data vulnerability in Amazon Opensearch 1.0.0/2.0.0/2.0.1 opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. | 8.8 |
2022-06-17 | CVE-2022-33915 | Race Condition vulnerability in Amazon Hotpatch 1.112/1.116 Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.3.5 are affected by a race condition that could lead to a local privilege escalation. | 7.0 |
2022-04-20 | CVE-2022-29527 | Incorrect Permission Assignment for Critical Resource vulnerability in Amazon SSM Agent Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate privileges to root. | 7.0 |
2022-04-19 | CVE-2021-3100 | Improper Privilege Management vulnerability in Amazon Log4Jhotpatch The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges. | 8.8 |
2022-04-19 | CVE-2022-0070 | Improper Privilege Management vulnerability in Amazon Log4Jhotpatch Incomplete fix for CVE-2021-3100. | 8.8 |