My IT security team keep flagging bitbucket server (well its elasticsearch service) as a threat due to the log4j vulnerability.
I upgraded to the lastest 7.19.3 which I thought from the release notes was deploying the "safe" 2.16 version but it turns out that I can still see 2.11.
Please provide a clear walk through on how to remove these files (which I believed are not used for logging by Bitbucket) and/or upgrade to 2.16.