Earlier quoted context omitted.
If you don’t use the code, you’re not vulnerable > who should get the blame? The users? If you leverage a ton of open source deps, shit is going to happen. You should not blame anyone. But if you must, yes: blame the users that choose such piss-poor software.
Just because someone releases code with AS IS/NO WARRANTY/BLAH BLAH BLAH doesn't mean they should not get called out for introducing such a vuln. Yes, you chose the code, failed to evaluate it's security, etc, but at the end of they day, the Log4* devs made a very very bad decision. Sadly, because of it's deep use in so many projects, it has kind of become too big to fail. I doubt %1 of users will swap out the loggin…
Come to think of it, they wouldn't even have to search for any exploits. Just ask devs nicely to put the backdoor in and be done with it.