CVE-2022-0070: Log4j hot patch package privilege escalation
Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the Linux capabilities and cgroups of the target Java process that the hotpatch is applied to.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-0070?
CVE-2022-0070 is an incomplete fix for CVE-2021-3100, a vulnerability in the Apache Log4j hotpatch package.
How does CVE-2022-0070 affect the Amazon Log4jhotpatch software?
CVE-2022-0070 affects Amazon Log4jhotpatch versions up to and including 1.1-16.
What does CVE-2022-0070 do?
CVE-2022-0070 explicitly mimics the Linux capabilities and cgroups of the target Java process that the hotpatch is applied to.
What is the severity of CVE-2022-0070?
CVE-2022-0070 has a severity value of 8.8, which is considered high.
How can I fix CVE-2022-0070?
To fix CVE-2022-0070, you should update the Apache Log4j hotpatch package to a version that includes a complete fix for CVE-2021-3100.