Apache Log4j2 versions 2.14.1 and below proof of concept
remote code execution exploit. JNDI features used in configuration,
log messages, and parameters do not protect against attacker
controlled LDAP and other JNDI related endpoints. An attacker who
can control log messages or log message parameters can execute
arbitrary code loaded from LDAP servers when message lookup
substitution is enabled.

