Lucene search

K
amazonAmazonALAS-2023-1866
HistoryOct 12, 2023 - 3:48 p.m.

Important: amazon-ssm-agent

2023-10-1215:48:00
alas.aws.amazon.com
24
amazon-ssm-agent
update
cve-2023-24540
cve-2021-43565
cve-2022-41723
red hat
mitre
unix

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.024 Low

EPSS

Percentile

90.0%

Issue Overview:

2023-10-30: CVE-2023-24540 was added to this advisory.

The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server. (CVE-2021-43565)

http2/hpack: avoid quadratic complexity in hpack decoding (CVE-2022-41723)

Templates did not properly consider backticks (`) as Javascript string delimiters, and as such did
not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template
contained a Go template action within a Javascript template literal, the contents of the action could
be used to terminate the literal, injecting arbitrary Javascript code into the Go template. (CVE-2023-24538)

html/template: improper handling of JavaScript whitespace.

Not all valid JavaScript whitespace characters were considered to be whitespace. Templates containing whitespace characters outside of the character set “\t\n\f\r\u0020\u2028\u2029” in JavaScript contexts that also contain actions may not be properly sanitized during execution. (CVE-2023-24540)

Affected Packages:

amazon-ssm-agent

Issue Correction:
Run yum update amazon-ssm-agent to update your system.

New Packages:

src:  
    amazon-ssm-agent-3.2.1705.0-1.amzn1.src  
  
x86_64:  
    amazon-ssm-agent-debuginfo-3.2.1705.0-1.amzn1.x86_64  
    amazon-ssm-agent-3.2.1705.0-1.amzn1.x86_64  

Additional References

Red Hat: CVE-2021-43565, CVE-2022-41723, CVE-2023-24538, CVE-2023-24540

Mitre: CVE-2021-43565, CVE-2022-41723, CVE-2023-24538, CVE-2023-24540

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.024 Low

EPSS

Percentile

90.0%