forked from phoedos/pmd

Update log4 to harden defaults. Based on CVE-2021-45046 the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. for more details CVE-2021-45046 (https://nvd.nist.gov/vuln/detail/CVE-2021-45046)