WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity SINGLE SOURCE

Lightwell project filters out 400 Java library security flaws

From below of long thin identical blue cables connected to small round electrical connectors
Illustrative photo.Photo by Brett Sayles on Pexels

What happened

Lightwell, the open-source (published so anyone may read, use and change the code) security initiative set up by IBM and Red Hat, has identified more than 400 previously undiscovered vulnerabilities in widely used Java libraries — and now the companies are inviting customers to submit their own code dependencies to a new service, Lightwell Clearinghouse, for review. They’ll be looking for bugs such as the critical sandbox bypass in Java template engine Thymeleaf , with a CVSS score of 9.1, discovered in April. Red Hat is a software company based in Raleigh.

IBM and Red Hat announced in May that they would commit 20,000 engineers and $5 billion to the Lightwell project , combining their open-source engineering expertise, Red Hat’s community relationships, and AI-assisted engineering workflows. Their goal is not just to identify security issues, but also to introduce remediation software to address them.

Azul has introduced free vulnerability risk assessment for Java Virtual Machines . Lightwell is not the only player in town when it comes to identifying and fixing Java vulnerabilities.

Key facts

  • IBM and Red Hat — announced: in May that they would commit 20,000 engineers and $5 billion to the Lightwell project , combining their open-source engineering expertise, Red Hat’s community relationships, and AI-assisted engineering workflows
  • Azul has — introduced: free vulnerability risk assessment for Java Virtual Machines

Sources & evidence