Out of Sight, Still at Risk: The Lifecycle of Transitive Vulnerabilities in Maven

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Przymus, Piotr, Fejzer, Mikołaj, Narębski, Jakub, Rykaczewski, Krzysztof, Stencel, Krzysztof
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866915231678070784
author Przymus, Piotr
Fejzer, Mikołaj
Narębski, Jakub
Rykaczewski, Krzysztof
Stencel, Krzysztof
author_facet Przymus, Piotr
Fejzer, Mikołaj
Narębski, Jakub
Rykaczewski, Krzysztof
Stencel, Krzysztof
contents The modern software development landscape heavily relies on transitive dependencies. They enable seamless integration of third-party libraries. However, they also introduce security challenges. Transitive vulnerabilities that arise from indirect dependencies expose projects to risks associated with Common Vulnerabilities and Exposures (CVEs). It happens even when direct dependencies remain secure. This paper examines the lifecycle of transitive vulnerabilities in the Maven ecosystem. We employ survival analysis to measure the time projects remain exposed after a CVE is introduced. Using a large dataset of Maven projects, we identify factors that influence the resolution of these vulnerabilities. Our findings offer practical advice on improving dependency management.
format Preprint
id arxiv_https___arxiv_org_abs_2504_04803
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Out of Sight, Still at Risk: The Lifecycle of Transitive Vulnerabilities in Maven
Przymus, Piotr
Fejzer, Mikołaj
Narębski, Jakub
Rykaczewski, Krzysztof
Stencel, Krzysztof
Software Engineering
Cryptography and Security
The modern software development landscape heavily relies on transitive dependencies. They enable seamless integration of third-party libraries. However, they also introduce security challenges. Transitive vulnerabilities that arise from indirect dependencies expose projects to risks associated with Common Vulnerabilities and Exposures (CVEs). It happens even when direct dependencies remain secure. This paper examines the lifecycle of transitive vulnerabilities in the Maven ecosystem. We employ survival analysis to measure the time projects remain exposed after a CVE is introduced. Using a large dataset of Maven projects, we identify factors that influence the resolution of these vulnerabilities. Our findings offer practical advice on improving dependency management.
title Out of Sight, Still at Risk: The Lifecycle of Transitive Vulnerabilities in Maven
topic Software Engineering
Cryptography and Security
url https://arxiv.org/abs/2504.04803