Open Source Vulnerability Notification
Open Source Vulnerability Notification
复制标题
开源漏洞通知
DOI:
10.1007/978-3-030-20883-7_2
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
Prakash, Atul
中科院分区:
文献类型:
--
作者:
Carlson, Brandon;Leach, Kevin;Marinov, Darko;Nagappan, Meiyappan;Prakash, Atul
The use of third-party libraries to manage software complexity can expose open source software projects to vulnerabilities. However, project owners do not currently have a standard way to enable private disclosure of potential security vulnerabilities. This neglect may be caused in part by having no template to follow for disclosing such vulnerabilities. We analyzed 600 GitHub projects to determine how many projects contained a vulnerable dependency and whether the projects had a process in place to privately communicate security issues. We found that 385 out of 600 open source Java projects contained at least one vulnerable dependency, and only 13 of those 385 projects had a security vulnerability reporting process. That is, 96.6% of the projects with a vulnerability didnothave a security notification process in place to allow for private disclosure. In determining whether the projects even had contact information publicly available, we found that 19.8% had no contact information publicly available, let alone a security vulnerability reporting process. We suggest two methods to allow for community members to privately disclose potential security vulnerabilities.
DOI:
--
发表时间:
1997
期刊:
Request for Comments
影响因子:
--
作者:
D. Crocker
通讯作者:
D. Crocker
DOI:
--
发表时间:
2019
期刊:
影响因子:
--
作者:
Y. Shafranovich;Edwin Foudil
通讯作者:
Edwin Foudil