Get notified about vulnerabilities, emergency patches, and interim mitigations for issues affecting Koha AMI customers on AWS Marketplace.
After an AMI upgrade or Auto Scaling Group instance replacement, the persistent data EBS volume (labeled 'kohadata') is not automatically detected and mounted by the new instance. The instance boots from the new AMI with empty default data, and the customer's library data appears lost until the volume is manually mounted and migrated.
When updating an existing KohaSupport CloudFormation stack to a new AMI version, the stack update may fail with an error referencing a missing SubnetList or AllSubnetsToUse attribute. This is caused by CloudFormation reusing a cached Lambda response from the original stack creation.
When S3 backup is enabled during CloudFormation stack creation, the backup timer is silently not configured on first boot. Backups never run despite the option being set.
Custom themes may fail to load essential JavaScript files, breaking search and menu toggles.
The Koha data EBS volume on Standard tier instances was not encrypted at rest. New Standard tier stacks launched from the patched AMI use a KMS customer-managed key (CMK) with automatic annual rotation.
Domain setup arguments are not correctly parsed during installation, causing domain configuration to fail.
The koha-setup-domains binary is missing from all Koha AMIs due to a configuration oversight.
CloudFormation stack updates fail when the SSM Command document is modified.
AMI upgrade causes 500 errors due to password mismatch between Plack and MySQL.
Languages selected during installation are not installed, and the OPAC REST API may return a 503 error.
Custom CSS set in the OPACUserCSS system preference is not applied to the OPAC.
Password resets fail with 'env: '/bin/admin/set_password.pl': No such file or directory'.
This is a placeholder advisory published to demonstrate the KohaSupport advisory system. No action is required.