Apache Log4j2 JNDI features do not protect against attacker
controlled LDAP and other JNDI related endpoints. An attacker
who can control log messages or paramters can execute arbitrary
code from attacker-controller LDAP servers when message lookup
substitution is enabled.