First published: Tue Apr 19 2022(Updated: )
Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the Linux capabilities and cgroups of the target Java process that the hotpatch is applied to.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Log4jhotpatch | <1.1-16 | |
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0070 is an incomplete fix for CVE-2021-3100, a vulnerability in the Apache Log4j hotpatch package.
CVE-2022-0070 affects Amazon Log4jhotpatch versions up to and including 1.1-16.
CVE-2022-0070 explicitly mimics the Linux capabilities and cgroups of the target Java process that the hotpatch is applied to.
CVE-2022-0070 has a severity value of 8.8, which is considered high.
To fix CVE-2022-0070, you should update the Apache Log4j hotpatch package to a version that includes a complete fix for CVE-2021-3100.