New flaw is much less severe than the Log4jshell vulnerability, but admins are advised to update Log4j once again