First published: Tue Apr 19 2022(Updated: )
The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Log4jhotpatch | <1.1-13 | |
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Apache Log4j hotpatch package vulnerability is CVE-2021-3100.
The severity of the Apache Log4j hotpatch package vulnerability (CVE-2021-3100) is high with a CVSS score of 8.8.
The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges.
The Apache Log4j hotpatch package (log4j-cve-2021-44228-hotpatch-1.1-13) is affected by this vulnerability.
To fix the Apache Log4j hotpatch package vulnerability (CVE-2021-3100), update to a version that addresses the issue, such as log4j-cve-2021-44228-hotpatch-1.1-13 or later.