log4j 1.x has several vulnerabilities. Although I don't know if they apply to the simple way I am using the library, it should be upgraded.