2021
DOI: 10.48550/arxiv.2108.06259
|View full text |Cite
Preprint
|
Sign up to set email alerts
|

VulnEx: Exploring Open-Source Software Vulnerabilities in Large Development Organizations to Understand Risk Exposure

Abstract: Figure 1: VULNEX is a tool for the investigation of exposure to open-source software vulnerabilities on an organization-wide level.The tool shows repositories, modules, libraries, vulnerabilities in a tree representation (A), and meta-information about each entry (B), such as the CVSS score. We can see that the "low-marmoset" repository is exposed to severe vulnerabilities, three critical and seven high. Two of the critical vulnerabilities are originating from the activemq-all indicating that the library shoul… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
1
0

Year Published

2024
2024
2024
2024

Publication Types

Select...
1

Relationship

0
1

Authors

Journals

citations
Cited by 1 publication
(1 citation statement)
references
References 21 publications
(28 reference statements)
0
1
0
Order By: Relevance
“…The research conducted by Dennig et al [42] on open-source software vulnerabilities in large organisations underscores a broader concept in cybersecurity: the significance of identifying third-party security risks. This study reveals how vulnerabilities in external software components, often integrated into larger systems, pose substantial risks.…”
Section: Third-party and Supply Chain Cybersecuritymentioning
confidence: 99%
“…The research conducted by Dennig et al [42] on open-source software vulnerabilities in large organisations underscores a broader concept in cybersecurity: the significance of identifying third-party security risks. This study reveals how vulnerabilities in external software components, often integrated into larger systems, pose substantial risks.…”
Section: Third-party and Supply Chain Cybersecuritymentioning
confidence: 99%