Hi Rajadharani,
Since the reported CVE is against the Log4j dependencies bundled with Library Logging 1.13.0, I would recommend checking the module's dependency tree and the exact vulnerable component before applying a workaround.
A few things that may help narrow this down:
For the long-term resolution, the Library Logging maintainer would need to confirm whether a newer module version will update the affected Log4j dependencies.
For the client's risk assessment, I would recommend documenting the AWS Inspector finding and requesting an official confirmation from the module maintainer regarding applicability and the planned remediation. If the vulnerability is confirmed as applicable, the recommended mitigation should come from the maintainer rather than manually modifying the bundled dependencies.
Kindly mark this as the accepted answer if it helps.