On Friday, Apache released yet another patch for yet another log4j bug. The latest bug isnt a variant of the Log4Shell remote-code execution bug thats plagued IT teams since Dec. 10. The new bug has to do with Context Map lookups, not JNDI, instead of the Java Naming and Directory Interface (JNDI) lookups to an LDAP server that allow attackers to execute code. The vulnerability affects all versions of the tool from 2-beta9 to 2.16, which Apache shipped last week.”]
Source: https://threatpost.com/third-log4j-bug-dos-apache-patch/177159/