This should be something that static code analyzers should pick up. If a dependency log4j dependency is <2.15, then it needs to be updated.
Just in time to ruin all of the reports project managers present to executives
Just in time to ruin all of the reports project managers present to executives
see https://github.com/apache/logging-log4j2/pull/608#issuecomme...
and you can just delete the affected class
The comment you cited is referring to the option to disable the vulnerable feature, not the vulnerable feature itself.
Per https://github.com/apache/logging-log4j2/pull/608#issuecomme... even log4j 1.x is vulnerable.