Vision: Identifying Affected Library Versions for Open Source Software Vulnerabilities
Abstract
Vulnerability reports play a crucial role in mitigating open-source software risks. Typically, the vulnerability report contains affected versions of a software. However, despite the validation by security expert who discovers and vendors who review, the affected versions are not always accurate. Especially, the complexity of maintaining its accuracy increases significantly when dealing with multiple versions and their differences. Several advances have been made to identify affected versions. However, they still face limitations. First, some existing approaches identify affected versions based on repository-hosting platforms (i.e., GitHub), but these versions are not always consistent with those in package registries (i.e., Maven). Second, existing approaches fail to distinguish the importance of different vulnerable methods and patched statements in face of vulnerabilities with multiple methods and change hunks.
BibTeX
@inproceedings{Wu-al:ASE24,
author = {Susheng Wu and
Ruisi Wang and
Kaifeng Huang and
Yiheng Cao and
Wenyan Song and
Zhuotong Zhou and
Yiheng Huang and
Bihuan Chen and
Xin Peng},
title = {Vision: Identifying Affected Library Versions for Open Source Software Vulnerabilities},
booktitle = {ASE},
pages = {1447--1459},
publisher = {{ACM}},
year = {2024},
}