CyberRota Analysis
AI-GeneratedA command injection vulnerability in the log4j-cve-2021-44228-hotpatch package on Amazon Linux versions prior to 1.3-9 allows local users to execute arbitrary commands with root privileges through specially crafted Java processes. This high-severity flaw poses a significant risk to system integrity and should be prioritized by organizations using affected versions of Amazon Linux and Java, particularly those with elevated user access. Immediate remediation is recommended to mitigate potential exploitation.
Original NVD Description
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.