Mitigating Persistence of Open-Source Vulnerabilities in Maven Ecosystem
Lyuye Zhang, Chengwei Liu, Sen Chen, Zhengzi Xu, Lingling Fan, Lida Zhao, Yiran Zhang, Yang Liu
Abstract
Vulnerabilities from third-party libraries (TPLs) have been unveiled to threaten the Maven ecosystem in the long term. Despite patches being released promptly after vulnerabilities are disclosed, the libraries and applications in the community still use the vulnerable versions, which makes the vulnerabilities persistent in the Maven ecosystem (e.g., the notorious Log4Shell still greatly influences the Maven ecosystem nowadays from 2021). Both academic and industrial researchers have proposed user-oriented standards and solutions to address vulnerabilities, while such solutions fail to tackle the ecosystem-wide persistent vulnerabilities because it requires a collective effort from the community to timely adopt patches without introducing breaking issues. To seek an ecosystem-wide solution, we first carried out an empirical study to examine the prevalence of persistent vulnerabilities in the Maven ecosystem. Then, we identified affected libraries for alerts by implementing an algorithm monitoring downstream dependents of vulnerabilities based on an up-to-date dependency graph. Based on them, we further quantitatively revealed that patches blocked by upstream libraries caused the persistence of vulnerabilities. After reviewing the drawbacks of existing countermeasures, to address them, we proposed a solution for range restoration (Ranger) to automatically restore the compatible and secure version ranges of dependencies for downstream dependents. The automatic restoration requires no manual effort from the community, and the code-centric compatibility assurance ensures smooth upgrades to patched versions. Moreover, Ranger along with the ecosystem monitoring can timely alert developers of blocking libraries and suggest flexible version ranges to rapidly unblock patch versions. By evaluation, Ranger could restore 75.64% of ranges which automatically remediated 90.32% of vulnerable downstream projects.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers10
- Empirical Analysis of Vulnerabilities Life Cycle in Golang EcosystemJinchang Hu, Lyuye Zhang, Chengwei Liu, Sen Yang et al.ICSE 2024 · 10 citations
- PatchFinder: A Two-Phase Approach to Security Patch Tracing for Disclosed Vulnerabilities in Open-Source SoftwareKaixuan Li, Jian Zhang, Sen Chen, Han Liu et al.ISSTA 2024 · 8 citations
- Who is the Real Hero? Measuring Developer Contribution via Multi-Dimensional Data IntegrationYuqiang Sun, Zhengzi Xu, Chengwei Liu, Yiran Zhang et al.ASE 2023 · 4 citations
- Fixing Outside the Box: Uncovering Tactics for Open-Source Security Issue ManagementLyuye Zhang, Jiahui Wu, Chengwei Liu, Kaixuan Li et al.ISSTA 2025 · 3 citations
- Vulnerability-Affected Versions Identification: How Far Are We?Xingchu Chen, Chengwei Liu, Jialun Cao, Yang Xiao et al.ASE 2025 · 3 citations
Builds on9
- Demystifying the Vulnerability Propagation and Its Evolution via Dependency Trees in the NPM EcosystemChengwei Liu, Sen Chen, Lingling Fan, Bihuan Chen et al.ICSE 2022 · 94 citations
- ATVHUNTER: Reliable Version Detection of Third-Party Libraries for Vulnerability Identification in Android ApplicationsXian Zhan, Lingling Fan, Sen Chen, Feng Wu et al.ICSE 2021 · 85 citations
- A Qualitative Study of Dependency Management and Its Security ImplicationsIvan Pashchenko, Duc-Ly Vu, Fabio MassacciCCS 2020 · 84 citations
- Software Composition Analysis for Vulnerability Detection: An Empirical Study on Java ProjectsLida Zhao, Sen Chen, Zhengzi Xu, Chengwei Liu et al.FSE 2023 · 42 citations
- Understanding the Threats of Upstream Vulnerabilities to Downstream Projects in the Maven EcosystemYulun Wu, Zeliang Yu, Ming Wen, Qiang Li et al.ICSE 2023 · 41 citations
Related papers
- Compatible Remediation on Vulnerabilities from Third-Party Libraries for Java ProjectsLyuye Zhang, Chengwei Liu, Zhengzi Xu, Sen Chen et al.ICSE 2023 · 19 citations
- AROMA: Automatic Reproduction of Maven ArtifactsMehdi Keshani, Tudor-Gabriel Velican, Gideon Bot, Sebastian ProkschFSE 2024 · 9 citations
- Death Is Not the End: a Longitudinal Study on the Impact of Automatic Updates on Container Vulnerability LifespansSimge Tekin, Octavian Suciu, Sungsu Kwag, Yonghwi Kwon et al.S&P 2026 · 1 citation
- Has My Release Disobeyed Semantic Versioning? Static Detection Based on Semantic DifferencingLyuye Zhang, Chengwei Liu, Zhengzi Xu, Sen Chen et al.ASE 2022 · 30 citations
- Agent-Based Automated Remediation for Vulnerabilities in Maven ProjectsLyuye Zhang, He Ye, Federica Sarro, Yuqiang Sun et al.OOPSLA 2026
