It seems to me like some of the provided sample projects depend on a vulnerable log4j version.
The oauth2-server which is used in several chapters loads log4j version 2.12.1 for example.
I think you might want to consider mitigating 1 this vulnerability, even though these projects are only intended for teaching purposes.