Hi Paul,

>My personal opinion  is that these are almost no risk for OS/2 - we
>don't have mod_lua, so  that rules out CVE-2021-44790; and
>CVE-2021-44224 is only for a specific use case (forward proxy

FWIW, I came to the same conclusion when I first read the CVEs.  They were
not sufficiently interesting to be worth discussing on the apache list.

Now, the Log4J CVE, even though it doesn't affect our platform, is more
than a litte interesting.


