On the Discoverability of npm Vulnerabilities in Node.js Projects

可发现性 计算机科学 依赖关系(UML) 脆弱性(计算) 计算机安全 万维网 软件工程
作者
Mahmoud Alfadel,Diego Elias Costa,Emad Shihab,Bram Adams
出处
期刊:ACM Transactions on Software Engineering and Methodology [Association for Computing Machinery]
卷期号:32 (4): 1-27 被引量:9
标识
DOI:10.1145/3571848
摘要

The reliance on vulnerable dependencies is a major threat to software systems. Dependency vulnerabilities are common and remain undisclosed for years. However, once the vulnerability is discovered and publicly known to the community, the risk of exploitation reaches its peak, and developers have to work fast to remediate the problem. While there has been a lot of research to characterize vulnerabilities in software ecosystems, none have explored the problem taking the discoverability into account. Therefore, we perform a large-scale empirical study examining 6,546 Node.js applications. We define three discoverability levels based on vulnerabilities lifecycle (undisclosed, reported, and public). We find that although the majority of the affected applications (99.42%) depend on undisclosed vulnerable packages, 206 (4.63%) applications were exposed to dependencies with public vulnerabilities. The major culprit for the applications being affected by public vulnerabilities is the lack of dependency updates; in 90.8% of the cases, a fix is available but not patched by application maintainers. Moreover, we find that applications remain affected by public vulnerabilities for a long time (103 days). Finally, we devise DepReveal, a tool that supports our discoverability analysis approach, to help developers better understand vulnerabilities in their application dependencies and plan their project maintenance.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
爆米花应助安于心采纳,获得10
刚刚
dann发布了新的文献求助30
1秒前
Zxc发布了新的文献求助10
3秒前
qq完成签到,获得积分10
4秒前
5秒前
充电宝应助Sue采纳,获得10
5秒前
ddly完成签到 ,获得积分10
7秒前
Alice完成签到,获得积分10
7秒前
7秒前
xie69完成签到,获得积分10
7秒前
Zxc完成签到,获得积分20
9秒前
10秒前
11秒前
12秒前
ONEACCOUNT发布了新的文献求助10
12秒前
ljx完成签到 ,获得积分10
13秒前
13秒前
14秒前
内向苡完成签到,获得积分10
15秒前
英俊的铭应助早睡早起采纳,获得10
16秒前
追寻迎夏完成签到,获得积分10
16秒前
研友_LN3xyn完成签到,获得积分10
16秒前
17秒前
居居侠发布了新的文献求助10
17秒前
安于心发布了新的文献求助10
17秒前
柚子青芒发布了新的文献求助20
18秒前
杰尼龟的鱼完成签到 ,获得积分10
18秒前
aaa完成签到,获得积分10
19秒前
慕青应助够了采纳,获得10
20秒前
日常常完成签到,获得积分10
21秒前
Proddy发布了新的文献求助10
21秒前
饺子生面包完成签到 ,获得积分10
21秒前
MADAO完成签到 ,获得积分10
21秒前
冷酷孤风完成签到,获得积分10
22秒前
落寞剑成完成签到 ,获得积分10
23秒前
STH完成签到 ,获得积分10
23秒前
24秒前
大紫罗兰馒头完成签到 ,获得积分10
25秒前
丛玉林完成签到,获得积分10
26秒前
27秒前
高分求助中
Applied Survey Data Analysis (第三版, 2025) 800
Narcissistic Personality Disorder 700
Assessing and Diagnosing Young Children with Neurodevelopmental Disorders (2nd Edition) 700
Handbook of Experimental Social Psychology 500
The Martian climate revisited: atmosphere and environment of a desert planet 500
Transnational East Asian Studies 400
Towards a spatial history of contemporary art in China 400
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 物理 生物化学 纳米技术 计算机科学 化学工程 内科学 复合材料 物理化学 电极 遗传学 量子力学 基因 冶金 催化作用
热门帖子
关注 科研通微信公众号,转发送积分 3845729
求助须知:如何正确求助?哪些是违规求助? 3388049
关于积分的说明 10551625
捐赠科研通 3108709
什么是DOI,文献DOI怎么找? 1713014
邀请新用户注册赠送积分活动 824576
科研通“疑难数据库(出版商)”最低求助积分说明 774891