Examples of the Log4jAttackSurface exploited in the wild
github.com
github.com
It uses log4j 1.x, and the maintainer of that has confirmed there's no vulnerability, initially it was thought that there could be if you used the JmsAppender, but it turns out that's not the case.