Nils Breunese <nils at breun.nl> wrote: > For versions of Log4J 2.x older than these properties are not read yet. (…) I meant to write: For versions of Log4J 2.x older than *2.10* these properties are not read yet, so you can’t use the properties to mitigate the vulnerability if you’re using Log4J < 2.10. Nils.