Home » Database

AVID-2026-R0931

Description

Log4j hot patch package privilege escalation (CVE-2022-0070)

Details

Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the Linux capabilities and cgroups of the target Java process that the hotpatch is applied to.

Reason for inclusion in AVID: CVE-2022-0070 describes a privilege escalation vulnerability in the Apache Log4j hotpatch package, a software component that can be part of AI system deployment stacks (Java-based services, logging pipelines, etc.). This is a software supply chain issue affecting components used to build/run AI systems, with a high-severity security impact (local escalation, high confidentiality/integrity/availability impact). The report includes CVSS details and references, providing clear evidence.

References

Affected or Relevant Artifacts

  • Developer: Amazon Web Services
  • Deployer: Amazon Web Services
  • Artifact Details:
TypeName
Systemlog4j-cve-2021-44228-hotpatch

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Base Score8.8
Base Severity🔴 High
Attack VectorLOCAL
Attack Complexity🟢 Low
Privileges Required🟢 Low
User InteractionNONE
ScopeCHANGED
Confidentiality Impact🔴 High
Integrity Impact🔴 High
Availability Impact🔴 High

CWE

IDDescription
CWE-250CWE-250 Execution with Unnecessary Privileges

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2022-04-19
  • Version: 0.3.3
  • AVID Entry