The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges.
2022-04-19T23:15:13.020
2024-11-21T06:20:53.487
Modified
CVSSv3.1: 8.8 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | amazon | log4jhotpatch | < 1.1-13 | Yes |
Application | linux | linux_kernel | - | No |