Or maybe someone had to run some scanning tool which reported 'no vulnerabilities'.
Exploiting log4j requires logging to be influenced by user input. Even if an application includes a vulnerable log4j but doesn't bother to log anything there's zero risk. In that case apathy saved you ;)
Comments
Maybe they only use the log4j test script ;)
Or maybe someone had to run some scanning tool which reported 'no vulnerabilities'.
Exploiting log4j requires logging to be influenced by user input. Even if an application includes a vulnerable log4j but doesn't bother to log anything there's zero risk. In that case apathy saved you ;)