Log4j vulnerability

I would guess it can be checked on the karaf console using

system:property log4j2.formatMsgNoLookups

which should say “true” and not “null”.