Impact
An OS command injection flaw exists in the Amazon log4j-cve-2021-44228-hotpatch package used by Amazon Linux. The flaw allows a local user to cause a Java process to execute an arbitrary command with root privileges when the process’s executable path contains newline characters. This vulnerability falls under CWE‑78 and can be exploited to run any code, giving the attacker full control over the affected system.
Affected Systems
The affected package is Amazon:log4j-cve-2021-44228-hotpatch, all releases before 1.3-9 on Amazon Linux. Users on earlier versions are at risk.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, while the EPSS score is 1% and the issue is not listed in the CISA KEV catalog. The vulnerability requires local access and a Java process whose executable path contains embedded newlines, so an attacker must already have some local foothold. Nonetheless, the potential for arbitrary root‑level command execution makes the risk significant for impacted hosts.
OpenCVE Enrichment