Out of Sight, Still at Risk: The Lifecycle of Transitive Vulnerabilities in Maven
Fuente:
arXiv
Salvato in:
| Autori principali: | , , , , |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2025
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
| _version_ | 1866915231678070784 |
|---|---|
| author | Przymus, Piotr Fejzer, Mikołaj Narębski, Jakub Rykaczewski, Krzysztof Stencel, Krzysztof |
| author_facet | Przymus, Piotr Fejzer, Mikołaj Narębski, Jakub Rykaczewski, Krzysztof Stencel, Krzysztof |
| contents | The modern software development landscape heavily relies on transitive dependencies. They enable seamless integration of third-party libraries. However, they also introduce security challenges. Transitive vulnerabilities that arise from indirect dependencies expose projects to risks associated with Common Vulnerabilities and Exposures (CVEs). It happens even when direct dependencies remain secure. This paper examines the lifecycle of transitive vulnerabilities in the Maven ecosystem. We employ survival analysis to measure the time projects remain exposed after a CVE is introduced. Using a large dataset of Maven projects, we identify factors that influence the resolution of these vulnerabilities. Our findings offer practical advice on improving dependency management. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2504_04803 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Out of Sight, Still at Risk: The Lifecycle of Transitive Vulnerabilities in Maven Przymus, Piotr Fejzer, Mikołaj Narębski, Jakub Rykaczewski, Krzysztof Stencel, Krzysztof Software Engineering Cryptography and Security The modern software development landscape heavily relies on transitive dependencies. They enable seamless integration of third-party libraries. However, they also introduce security challenges. Transitive vulnerabilities that arise from indirect dependencies expose projects to risks associated with Common Vulnerabilities and Exposures (CVEs). It happens even when direct dependencies remain secure. This paper examines the lifecycle of transitive vulnerabilities in the Maven ecosystem. We employ survival analysis to measure the time projects remain exposed after a CVE is introduced. Using a large dataset of Maven projects, we identify factors that influence the resolution of these vulnerabilities. Our findings offer practical advice on improving dependency management. |
| title | Out of Sight, Still at Risk: The Lifecycle of Transitive Vulnerabilities in Maven |
| topic | Software Engineering Cryptography and Security |
| url | https://arxiv.org/abs/2504.04803 |