On Dec 11, 2021, at 11:24, Richard L. Hamilton wrote: > CVE-2021-44228 sounds kinda scary! We appear to have a jakarta-log4j port but it is version 1.x, not 2.