Does all Solr logging go through slf4j? If so, that should protect against this vulnerability.
If not, who has tested Solr with log4j 2.15.1? We are running 8.8.2. wunder Walter Underwood wun...@wunderwood.org http://observer.wunderwood.org/ (my blog)