CVE-2021-3100
published 2022-04-19CVE-2021-3100: Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the Linux…
PriorityP342high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.36%
28.4th percentile
Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the Linux capabilities and cgroups of the target Java process that the hotpatch is applied to.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amazon | log4jhotpatch | < 1.1-16 | 1.1-16 |
| amazon | log4jhotpatch | < 1.1-13 | 1.1-13 |
| amazon_web_services | log4j-cve-2021-44228-hotpatch | >= unspecified < 1.1-16 | 1.1-16 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x6m6-c6mx-qvf8: Incomplete fix for CVE-2021-3100
ghsa_unreviewed·2022-04-21·CVSS 8.8
CVE-2022-0070 [HIGH] CWE-269 GHSA-x6m6-c6mx-qvf8: Incomplete fix for CVE-2021-3100
Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the Linux capabilities and cgroups of the target Java process that the hotpatch is applied to.
GHSA
GHSA-24pr-9rc2-6xv5: The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1
ghsa_unreviewed·2022-04-21
CVE-2021-3100 [HIGH] CWE-269 GHSA-24pr-9rc2-6xv5: The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1
The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-12 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges.
No detection rules found.
No public exploits indexed.
Tenable
Hot Patches for Log4Shell Introduced Multiple Vulnerabilities in Amazon Web Services
blogs_tenable·2022-04-21
Hot Patches for Log4Shell Introduced Multiple Vulnerabilities in Amazon Web Services
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Unit42
AWS's Log4Shell Hot Patch Vulnerable to Container Escape and Privilege Escalation
blogs_unit42·2022-04-19·CVSS 8.8
CVE-2021-3100 [HIGH] AWS's Log4Shell Hot Patch Vulnerable to Container Escape and Privilege Escalation
Threat Research Center
Threat Research
Cloud Cybersecurity Research
## AWS's Log4Shell Hot Patch Vulnerable to Container Escape and Privilege Escalation
Yuval Avrahami
Published: April 19, 2022
Cloud Cybersecurity Research
Threat Research
Vulnerabilities
Apache Log4j
AWS
Container escape
Containers
CVE-2021-3100
CVE-2021-3101
CVE-2021-44228
CVE-2022-0070
CVE-2022-0071
Log4j
Privilege escalation
## Executive Summary
Following Log4Shell , AWS released several hot patch solutions that monitor for vulnerable Java applications and Java containers and patch them on the fly. Each solution suits a different environment, covering standalone servers, Kubernetes clusters, Elastic Container Service (ECS) clusters and Fargate. The hot patches aren't exclusive to AWS environment
Unit42
AWS's Log4Shell Hot Patch Vulnerable to Container Escape and Privilege Escalation
blogs_unit42·2022-04-19·CVSS 8.8
[HIGH] AWS's Log4Shell Hot Patch Vulnerable to Container Escape and Privilege Escalation
## Executive Summary
Following Log4Shell, AWS released several hot patch solutions that monitor for vulnerable Java applications and Java containers and patch them on the fly. Each solution suits a different environment, covering standalone servers, Kubernetes clusters, Elastic Container Service (ECS) clusters and Fargate. The hot patches aren't exclusive to AWS environments and can be installed onto any cloud or on-premises environment.
Unit 42 researchers identified severe security issues within these patching solutions and partnered with AWS to remediate them. After installing the patch service to a server or cluster, every container in that environment can exploit it to take over its underlying host. For example, if you installed the hot patch to a Kubernetes cluster, every container
2022-04-19
Published