There is no version of apache storm which doesn't use log4j 2.x version (which is affected by CVE-2021-44228 vulnerability). I found this fix on log4j website:y
google-maps-embed
picturefill
ipu
tinder
memberof
referer
data-loss
dcos
text-direction
number-systems
getforegroundwindow
sse4
datakey
qsplitter
yellow
cve-2022-22965
play-json
asp.net5
unicode-string
freetext
ms-access-forms
impex
flask-jwt-extended
social-networking
isometric
tensorboard
kotlin-stateflow
polymer-elements
spa-template
reach