QID 353969
Date Published: 2022-07-05
QID 353969: Amazon Linux Security Advisory for log4j-cve-2021-44228-hotpatch : ALAS2-2022-1806
Versions of the apache log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.3-5 are affected by a race condition that could lead to a local privilege escalation. the apache log4j hotpatch is not a replacement for updating to a log4j version that mitigates( CVE-2021-44228 or( CVE-2021-45046, it provides a temporary mitigation to( CVE-2021-44228 by hotpatching local java virtual machines.
To do so, the hotpatch script iterates through all running java processes, performs several checks, and executes the java virtual machine with the same permissions and capabilities as the running process to load the hotpatch.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
- ALAS2-2022-1806 -
alas.aws.amazon.com/AL2/ALAS-2022-1806.html
CVEs related to QID 353969
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2-2022-1806 | Amazon Linux 2 |
|