Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-3101— Hotdog Container Escape

CVSS 8.8 · High EPSS 0.04% · P12
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-3101

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Hotdog Container Escape
Source: NVD (National Vulnerability Database)
Vulnerability Description
Hotdog, prior to v1.0.1, did not mimic the capabilities or the SELinux label of the target JVM process. This would allow a container to gain full privileges on the host, bypassing restrictions set on the container.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
带着不必要的权限执行
Source: NVD (National Vulnerability Database)
Vulnerability Title
Hotdog 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Hotdog是一组 OCI 挂钩。用于将 Log4j Hot Patch 注入容器。 Hotdog 1.0.1 版本之前存在安全漏洞,该漏洞源于没有模仿目标 JVM 进程的功能或 SELinux 标签。 这将允许容器在主机上获得完全权限,绕过对容器设置的限制。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Amazon Web ServicesHotdog unspecified ~ 1.0.1 -

II. Public POCs for CVE-2021-3101

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-3101

登录查看更多情报信息。

Same Patch Batch · Amazon Web Services · 2022-04-19 · 4 CVEs total

CVE-2021-31008.8 HIGHLog4j hot patch package privilege escalation
CVE-2022-00708.8 HIGHLog4j hot patch package privilege escalation
CVE-2022-00718.8 HIGHHotdog Container Escape

IV. Related Vulnerabilities

V. Comments for CVE-2021-3101

No comments yet


Leave a comment