The most humorous thing for me about this entire situation is that the way reporting is handle in many orgs is:
Central IT: Are we vulnerable in system X?
System owner: writes vendor
Vendor: No we are not vulnerable to that CVE, we are using Log4J V1
System owner: … the one that’s eol 2015, and has a bunch of other CVE’s including another RCE?
Vendor: yes
System owner:Are you going to issue an upgrade?
Vendor: No, we are not vulnerable to the latest CVE on V2 so we will not.
System vendor to central IT: They are using log4j V1, so not affected by the latest CVE, but we are vulnerable to other CVEs including RCE.
Central IT: Perfect, we’ll mark it down as no issues then, the Issue handling only covers the latest CVE.