Second Log4j vulnerability found, Apache Log4j 2.16.0 released

The CVE said the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations.

Article Link: Second Log4j vulnerability discovered, patch already released | ZDNet