In response to vulnerabilities in the log4j library, the THREDDS development team has released new versions of the TDS 4.6.x and 5.x. TDS 4.6.19 and TDS 5.3 user log4j 2.17.0, and address CVE-2021-44228, CVE-2021-45046, and CVE-2021-45105.
The TDS version 5.3 now uses the most recent release of netCDF-Java, 5.5.1, which additionally addresses CVE-2021-42550.
It is recommended that all TDS users upgrade to either 4.6.19 or 5.3. You can find the GitHub releases at https://github.com/Unidata/thredds/releases/tag/v4.6.19 and https://github.com/Unidata/tds/releases/tag/v5.3.