High severity8.8NVD Advisory· Published Apr 19, 2022· Updated Jun 17, 2026
CVE-2021-3100
CVE-2021-3100
Description
The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <1.1-13
- Range: unspecified
Patches
Vulnerability mechanics
References
3- unit42.paloaltonetworks.com/aws-log4shell-hot-patch-vulnerabilitiesnvdExploitThird Party Advisory
- alas.aws.amazon.com/AL2/ALAS-2021-1732.htmlnvdVendor Advisory
- alas.aws.amazon.com/ALAS-2021-1554.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.