Log4j CVE-2021-44832 (released 28th dec) - is ES vulnerable?

They said that there is no known vulnerabilities :

By default, Elasticsearch and Logstash have no known vulnerabilities to this as relevant configuration files are only writable by cluster administrators. We will release 7.16.3 and 6.8.23 to update Log4j to 2.17.1, targeting Jan 13.