Following Log4Shell, AWS (Amazon Web Services) has released several hot patch solutions that monitor vulnerable Java applications and Java containers and patch them immediately. Each solution is tailored to a different environment, covering standalone servers, Kubernetes clusters, Elastic Container Service (ECS) clusters, and Fargate. The hot patches are not exclusive to AWS environments and can be deployed in any cloud or on-premises environment.

Amazon Web Services (AWS) fixed four security issues in its hot patch from December that addressed the critical Log4Shell vulnerability (CVE-2021-44228) that affects cloud or on-premises environments running Java applications with a vulnerable version of the Log4j logging library or containers.
The hot patch packages from Amazon are not exclusive to AWS resources and allow a container to escape into the environment and take control of the host. The flaws could also be exploited via non- privileged processes to escalate privileges and execute code as if with root privileges.
The vulnerabilities are currently tracked as CVE-2021-3100, CVE-2021-3101, CVE-2022-0070, and CVE-2022-0071. All of them have been rated as high severity risks with a score of 8.8 out of 10.
Security researchers at Palo Alto Networks Unit 42 discovered that Amazon's Log4Shell hotfix solutions will continue to scan for Java processes and patch them on the fly without ensuring that the patched processes run under the restrictions imposed on the container.
Another problem created by Amazon's patch was that host processes were treated in a similar way, all of which received elevated privileges during the Log4Shell patch process.
Potentially, a hacker could install an unprivileged binary process called "java" and trick the repair service into running it with elevated privileges.
The Unit 42 team also published the following proof-of-concept (PoC) exploit video to demonstrate the container escape scenario:
The implementation details have been intentionally hidden to prevent directly using it in attacks and to give administrators time to apply available security updates.
Finding and correcting defects
Researchers at Palo Alto Networks discovered the security issues in the AWS patches six days after the hotfix was released and notified Amazon on December 21, 2021.
The AWS security team recognized the vulnerabilities and attempted to fix with a new update on December 23, 2021, but the changes proved insufficient.
In the months that followed, Unit 42 provided more information on how to bypass the new fixes, and as of April 4, 2022, the remaining issues were minimal.
On April 19, 2022, AWS released the final updates for the Log4Shell remediation solutions, which administrators can apply in one of the following ways:
- Kubernetes users can deploy to the latest version of Daemonset, which will not affect the Log4Shell patch
- Hotdog users can upgrade to the latest available version
- Standalone hosts can be upgraded using the commands:

The four vulnerabilities in the Log4Shell hot-patch, discovered by Palo Alto Networks' Unit 42, are as follows:
- CVE-2021-3100
- CVE-2022-0070
- CVE-2021-3101
- CVE-2022-0071
Amazon has also released a new advisory for the above vulnerabilities, providing official guidance on how to address the issues.
Section 42 warns against prioritizing fixing container escape flaws in Log4Shell, because the Log4j vulnerability is more serious and actively used.
Information source: bleepingcomputer.com
