Based on : https://github.com/advisories/GHSA-jfh8-c2jp-5v3q and https://www.lunasec.io/docs/blog/log4j-zero-day/ Log4j versions prior to 2.15.0 are subject to a remote code execution vulnerability via the ldap JNDI parser. Current version: [2.1 ](https://github.com/prometheus/client_java/blob/master/simpleclient_log4j2/pom.xml#L44)