Solr 7.7 in Mailcow at least contains a vulnerable Log4j version (2.11).
I’m not sure if the vulnerability can be exploited since Mailcow’s Solr is not reachable from the outside. It would probably also require some specially crafted emails to control the log messages, if this even works at all on Mailcow.
Until there is a fix or a confirmation that Mailcow is not affected, I removed the JndiLookup class as described here:
https://github.com/advisories/GHSA-jfh8-c2jp-5v3q