The Jenkins infrastructure and security teams have published a blog post that contains information about CVE-2021-44228 in the Apache Log4j 2 library:
The blog post will be updated if new information is discovered.https://www.jenkins.io/blog/2021/12/10/log4j2-rce-CVE-2021-44228/