Session

Poison Was the Cure: A Glimpse Into OSS Vulnerability Disclosure Practices

In open-source software (OSS), software vulnerabilities are at an all-time high. We conduct a study focusing on security advisories and bug bounty reports as perspectives for exploring OSS vulnerability disclosure practices. Findings reveal challenges in keeping pace with review rates, the absence of CVEs in the National Vulnerability Database, and subjective determination in filing CVE requests for vulnerabilities; thus, hindering the spread of alerts to affected projects. Furthermore, a majority of projects do not implement easy-to-configure software vulnerability management features. We offer actionable recommendations to enhance OSS project security, focusing on improving review rates, reinforcing CVE integration, and promoting robust vulnerability disclosure practices. Overall, we reveal gaps in the current OSS security landscape to provide valuable insights for practitioners, developers, and the broader OSS community.

Jessy Ayala

PhD Student at UC Irvine

Irvine, California, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top