Apache Log4j 2 vulnerability CVE-2021-44228

See the reply from @batmat in the Jenkins user mailing list.

That file location is a cache maintained by Apache Maven. If that is your Jenkins controller, it likely means that you’re making the mistake of building on the Jenkins controller. Don’t do that. Reasons why are described in