bottlerocket-os/hotdog

bottlerocket-os/hotdog

Releases7
Frequency2 months 1 week
Last Release
Stars42
Hotdog is a set of OCI hooks used to inject the Log4j Hot Patch into containers.

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH7.2 HIGH

Hotdog, prior to v1.0.1, did not mimic the capabilities or the SELinux label of the target JVM process. This would allow a container to gain full privileges on the host, bypassing restrictions set on the container.

8.8 HIGH7.2 HIGH

Incomplete fix for CVE-2021-3101. Hotdog, prior to v1.0.2, did not mimic the resource limits, device restrictions, or syscall filters of the target JVM process. This would allow a container to exhaust the resources of the host, modify devices, or make syscalls that would otherwise be blocked.