I found it is been discussed already on ticket #400. Sorry for the duplication.
I was wondering whether davmail uses apache log4j, which was found to have a serious serious security hole. If so, how can we solve the vulnerability?