qos-ch/slf4j

MavenGate (CVE)

amareshdlphx opened this issue · 0 comments

XFrog triggers an alert XRAY-589059 on packages:

  • org.slf4j:jul-to-slf4j
  • org.slf4j:slf4j-api

Looks like groupId domain org.slf4j can be claimed by malicious user.