qos-ch / slf4j

Simple Logging Facade for Java
http://www.slf4j.org
MIT License
2.32k stars 980 forks source link

MavenGate (CVE) #397

Open amareshdlphx opened 6 months ago

amareshdlphx commented 6 months ago

XFrog triggers an alert XRAY-589059 on packages:

Looks like groupId domain org.slf4j can be claimed by malicious user.