Boletines de Vulnerabilidades |
Reported Apache Log4j Hotpatch Issues |
|
| Software afectado | AmazonWS |
|
Initial Publication Date: 2022/04/19 14:30 PST CVE IDs: CVE-2021-3100, CVE-2021-3101, CVE-2022-0070, CVE-2022-0071 On December 12, 2021, Amazon publicly released a hotpatch for running Java VMs which disables the loading of the Java Naming and Directory Interface (JNDI) class. This hotpatch provides an immediate mitigation for critical issues within the open-source Apache “Log4j2" utility (CVE-2021-44228 and CVE-2021-45046) while allowing system administrators sufficient time to More info: https://aws.amazon.com/security/security-bulletins/AWS-2022-006/ |
|














