There is no version of apache storm which doesn't use log4j 2.x version (which is affected by CVE-2021-44228 vulnerability). I found this fix on log4j website:y
ibrokers
background-music
yubikey
require-method
tvos10
jdoodle
user-defined
cartalyst
installutil
private-repository
photoshop-sdk
sendmailr
system.net.mail
zabbix
fusioncharts
hiveql
casting
parquet-dataset
javascript-import
opencart
ipaas
asp.net-web-api
heic
web-notifications
servletexception
query-performance
cake-pattern
git-review
form-post
knowledge-management