log4j-1.2.17.jar missing from jetty folder
I read the security bullitins around this jar file coming up in security scans. I noticed that in one of my instances (test) for whatever reason that log4j.jar file is completly missing in the /jetty/lib/ext folder but yet the CF server is running fine. In our dev/prod instances though the log4j-1.2.17.jar is in the /jetty/lib/ext folder and can't be deleted or renamed becasue its in use even when the CF server is stopped.. I guess the question here is 1. Why would it be missing on one server but not the other (Identical deployment; Same versions; etc.). 2. Can these log4j versions be ignored as vulnerable. I know in previous discussions only certain CVES are mentioned but our scanners pick up reference to the jetty instance being vulnerable to.
CVE 2020-9488
CVE 2022-23302
CVE 2022-23305
CVE 2022-23307
