Lightwell project filters out 400 Java library security flaws
What happened
Lightwell, the open-source (published so anyone may read, use and change the code) security initiative set up by IBM and Red Hat, has identified more than 400 previously undiscovered vulnerabilities in widely used Java libraries — and now the companies are inviting customers to submit their own code dependencies to a new service, Lightwell Clearinghouse, for review. They’ll be looking for bugs such as the critical sandbox bypass in Java template engine Thymeleaf , with a CVSS score of 9.1, discovered in April. Red Hat is a software company based in Raleigh.
IBM and Red Hat announced in May that they would commit 20,000 engineers and $5 billion to the Lightwell project , combining their open-source engineering expertise, Red Hat’s community relationships, and AI-assisted engineering workflows. Their goal is not just to identify security issues, but also to introduce remediation software to address them.
Azul has introduced free vulnerability risk assessment for Java Virtual Machines . Lightwell is not the only player in town when it comes to identifying and fixing Java vulnerabilities.
Key facts
- IBM and Red Hat — announced: in May that they would commit 20,000 engineers and $5 billion to the Lightwell project , combining their open-source engineering expertise, Red Hat’s community relationships, and AI-assisted engineering workflows
- Azul has — introduced: free vulnerability risk assessment for Java Virtual Machines
Sources & evidence
- CSO Online Reporting source
Lightwell project filters out 400 Java library vulnerabilities ↗
https://www.csoonline.com/article/4233240/lightwell-project-filters-out-400-java-library-vulnerabilities-2.html