@snikket_im
Also worth noting about other #XMPP software:
- Jitsi Meet does use log4j in some components. Though it appears it probably wasn't vulnerable, the team have published a new release and it is definitely sensible to upgrade!
- Openfire was vulnerable and they have published a new release to which everyone should upgrade: https://discourse.igniterealtime.org/t/openfire-4-6-5-released/91108 (a workaround is also detailed)
- Tigase is another notable server written in Java, but it does not use log4j, so is not affected.