Lightwell finds 400+ vulnerabilities in Java libraries
Lightwell, the open-source security initiative by IBM and Red Hat, has identified more than 400 previously undiscovered vulnerabilities in widely used Java libraries, including a critical sandbox bypass in Thymeleaf with a CVSS score of 9.1. The companies opened the Lightwell Clearinghouse service for customers to submit their code dependencies and plan to backport fixes into production apps.
- Over 400 new vulnerabilities found in Java libraries
- Critical Thymeleaf sandbox bypass scored CVSS 9.1
- IBM and Red Hat committed $5B and 20,000 engineers
- Lightwell Clearinghouse accepts customer dependencies for review
Read next
Security