Lightwell project filters out 400 Java library vulnerabilities

Summary

The Lightwell project, a collaboration between IBM and Red Hat, has discovered over 400 new vulnerabilities in popular Java libraries. They are now offering a service called Lightwell Clearinghouse for customers to submit their code dependencies for review. This initiative aims to quickly identify and fix bugs, including critical ones like a sandbox bypass in Thymeleaf.

IFF Assessment

FRIEND

This article details efforts to proactively identify and fix vulnerabilities in widely used software, which directly benefits defenders by reducing the attack surface.

Severity

9.1 Critical

The article explicitly mentions a critical sandbox bypass vulnerability in the Java template engine Thymeleaf and states its CVSS score is 9.1.

Defender Context

The discovery of numerous previously unknown vulnerabilities in popular Java libraries highlights the ongoing risk posed by open-source software dependencies. Defenders should pay close attention to initiatives like Lightwell and ensure their organizations have robust processes for managing and patching third-party libraries to mitigate potential exploitation.

Read Full Story →