CVE-2022-0070: Amazon LOG4JHOTPATCH

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the Linux capabilities and cgroups of the target Java process that the hotpatch is applied to.

Affected products

  • Amazon LOG4JHOTPATCH: before 1.1-16 (fixed in 1.1-16)

Published 2022-04-19. Last modified 2026-06-17.