I am using, kafka-avro-serializer and I could not locate which version of log4j it uses internally for logging, so, I was wondering if it is impacted by the security vulnerability CVE-2021-44228? Also, which version does it use?
I checked the FAQs and the thread but I couldn't find anything specific to kafka-avro-serializer.
If the vulnerability depends on the version of kafka-avro-serializer being used, then, would really appreciate how I can identify that.
Thank you.