Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the Linux capabilities and cgroups of the target Java process that the hotpatch is applied to.
References
Link | Resource |
---|---|
https://alas.aws.amazon.com/cve/html/CVE-2022-0070.html | Vendor Advisory |
https://unit42.paloaltonetworks.com/aws-log4shell-hot-patch-vulnerabilities | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: palo_alto
Published: 2022-04-19T00:00:00
Updated: 2022-04-19T22:15:23
Reserved: 2021-12-28T00:00:00
Link: CVE-2022-0070
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-04-19T23:15:13.177
Modified: 2022-09-30T13:09:34.700
Link: CVE-2022-0070
JSON object: View
Redhat Information
No data.