Breaking News

Athena open-source defense coalition releases first ‘silent’ vulnerabilities

https://ift.tt/Q4S3s2u

Athena, Chainguard’s industry coalition for the orchestrated defense of open source software, today is publicly disclosing its first set of findings: 14 “silent” vulnerabilities all across Java projects, including one critical and one high-severity flaw. These bugs were previously fixed upstream but never received a CVE, leaving older versions exposed and invisible to scanners.

The full list is in Chainguard’s public patch repository.

Members  of the coalition can submit any frontier AI model vulnerability findings to Athena. According to Athena, “Operationally, they submit findings through an encrypted portal. We deduplicate and enrich each finding, tracing when the flaw was introduced, whether it’s already fixed at HEAD, and publish the metadata as a private OSV feed.”

The reason this group of vulnerabilities was chosen is because none are a live zero-day, and as such is the right place to run each step of vulnerability remediation  — patch, advisory, partner mitigation, shipped artifact) –and find out what breaks before the thousands behind them arrive. Also, there is no path of accept a fix for the affected versions.

If the bug still exists at the latest version, disclosure runs through the Linux Foundation’s Akrites initiative, and the maintainers ship the fix. If it’s already fixed at HEAD and nobody said so, Chainguard drives the disclosure.

What Athena does it publish patch files in a public GitHub repository, andy anyone can read them and decide to apply them to their own build.  A free, public Chainguard VEX feed with the affected versions enumerated. Athena partners are plugged into it: shield partners are issuing non-patch mitigations, and surface partners can tell you when an affected dependency is in your stack.’ The patch itself is free, and every one of the 14 affected Java projects has a remediated version in Chainguard repository, published at the same time as the advisory, the company wrote in its blog announcement.

“Adopting it is a one-line change: swap the vulnerable artifact in your lockfile for Chainguard’s version and rebuild.” the announcement said. “It carries the same package coordinates your application already uses, plus a Chainguard version qualifier (-0cgr.n). No code changes, no major version upgrade. If a maintainer later adopts a backport we authored, we deprecate ours and point at upstream, so you always land on the canonical fix.

 

The post Athena open-source defense coalition releases first ‘silent’ vulnerabilities appeared first on SD Times.



Tech Developers

No comments