There is no version of apache storm which doesn't use log4j 2.x version (which is affected by CVE-2021-44228 vulnerability). I found this fix on log4j website:y
powershell-7.0
django-widget-tweaks
file-descriptor
getattr
wamp64
spark-structured-streaming
symfony-config-component
getresponse
icalendar
.app
huxtable
qpropertyanimation
spring
forestadmin
qfuture
zic
epiphany
preflight
accounting
concurrent-programming
roadmap
pyc
docusaurus
print-css
longtable
apache-httpclient-5.x
beagle
jaxb2-annotate-plugin
http4k
ydn-db