Compatible Remediation on Vulnerabilities from Third-Party Libraries for Java Projects
Lyuye Zhang, Chengwei Liu, Zhengzi Xu, Sen Chen, Lingling Fan, Lida Zhao, Jiahui Wu, Yang Liu
Abstract
With the increasing disclosure of vulnerabilities in open-source software, software composition analysis (SCA) has been widely applied to reveal third-party libraries and the associated vulnerabilities in software projects. Beyond the revelation, SCA tools adopt various remediation strategies to fix vulnerabilities, the quality of which varies substantially. However, ineffective remediation could induce side effects, such as compi-lation failures, which impede acceptance by users. According to our studies, existing SCA tools could not correctly handle the concerns of users regarding the compatibility of remediated projects. To this end, we propose Compatible Remediation of Third-party libraries (CORAL) for Maven projects to fix vulnerabilities without breaking the projects. The evaluation proved that Coralnot only fixed 87.56% of vulnerabilities which outperformed other tools (best 75.32%) and achieved a 98.67% successful compilation rate and a 92.96% successful unit test rate. Furthermore, we found that 78.45% of vulnerabilities in popular Maven projects could be fixed without breaking the compilation, and the rest of the vulnerabilities (21.55%) could either be fixed by upgrades that break the compilations or even be impossible to fix by upgrading.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9f8ae7bd-039a-4e75-b592-8ccc7022f713Cited by top-tier papers8
- Mitigating Persistence of Open-Source Vulnerabilities in Maven EcosystemLyuye Zhang, Chengwei Liu, Sen Chen, Zhengzi Xu et al.ASE 2023 · 25 citations
- Understanding and Remediating Open-Source License Incompatibilities in the PyPI EcosystemWeiwei Xu, Hao He, Kai Gao, Minghui ZhouASE 2023 · 13 citations
- Empirical Analysis of Vulnerabilities Life Cycle in Golang EcosystemJinchang Hu, Lyuye Zhang, Chengwei Liu, Sen Yang et al.ICSE 2024 · 10 citations
- Who is the Real Hero? Measuring Developer Contribution via Multi-Dimensional Data IntegrationYuqiang Sun, Zhengzi Xu, Chengwei Liu, Yiran Zhang et al.ASE 2023 · 4 citations
- Fixing Outside the Box: Uncovering Tactics for Open-Source Security Issue ManagementLyuye Zhang, Jiahui Wu, Chengwei Liu, Kaixuan Li et al.ISSTA 2025 · 3 citations
Builds on7
- Demystifying the Vulnerability Propagation and Its Evolution via Dependency Trees in the NPM EcosystemChengwei Liu, Sen Chen, Lingling Fan, Bihuan Chen et al.ICSE 2022 · 94 citations
- ATVHUNTER: Reliable Version Detection of Third-Party Libraries for Vulnerability Identification in Android ApplicationsXian Zhan, Lingling Fan, Sen Chen, Feng Wu et al.ICSE 2021 · 85 citations
- Towards Understanding Third-party Library Dependency in C/C++ EcosystemWei Tang, Zhengzi Xu, Chengwei Liu, Jiahui Wu et al.ASE 2022 · 64 citations
- Automated Third-Party Library Detection for Android Applications: Are We There Yet?Xian Zhan, Lingling Fan, Tianming Liu, Sen Chen et al.ASE 2020 · 55 citations
- A longitudinal analysis of bloated Java dependenciesCésar Soto-Valero, Thomas Durieux, Benoit BaudryFSE 2021 · 47 citations
Related papers
- Software Composition Analysis for Vulnerability Detection: An Empirical Study on Java ProjectsLida Zhao, Sen Chen, Zhengzi Xu, Chengwei Liu et al.FSE 2023 · 42 citations
- Understanding the Threats of Upstream Vulnerabilities to Downstream Projects in the Maven EcosystemYulun Wu, Zeliang Yu, Ming Wen, Qiang Li et al.ICSE 2023 · 41 citations
- Context Matters: Qualitative Insights into Developers' Approaches and Challenges with Software Composition AnalysisElizabeth Lin, Sparsha Gowda, William Enck, Dominik WermkeUSENIX Security 2025
- OSSFP: Precise and Scalable C/C++ Third-Party Library Detection using Fingerprinting FunctionsJiahui Wu, Zhengzi Xu, Wei Tang, Lyuye Zhang et al.ICSE 2023 · 29 citations
- VulSCA: A Community-Level SCA Approach for Accurate C/C++ Supply Chain Vulnerability AnalysisYutao Hu, Chaofan Li, Yueming Wu, Yifeng Cai et al.NDSS 2026 · 1 citation
