Report Shines Spotlight on 91 Vulnerabilities Fixed in Latest Update to Spring Framework
Sonatype says 91 Spring vulnerabilities affecting more than 209,000 software components highlight how AI is accelerating vulnerability discovery and creating a new patching challenge for DevSecOps teams.
A report from Sonatype has highlighted over 91 vulnerabilities that have been addressed in the most recent update to the Spring framework for deploying Java applications, announced by Broadcom earlier this month. This update affects 209,569 software components that require updating. Brian Fox, Sonatype's Chief Technology Officer, explained that the extensive number of vulnerabilities released concurrently signals that providers of major software platforms are striving to address significant technical debt before vulnerabilities are discovered and exploited by cybercriminals, who increasingly leverage advanced AI models.
These platform providers already possess access to similar AI models, granting them an edge in identifying and mitigating vulnerabilities before they can be exploited by adversaries. From March to April, Broadcom issued more than 1,700% increase in advisories, according to the Sonatype report. DevSecOps teams now face the challenge of simultaneously updating multiple frameworks and platforms due to the rush by providers to rectify technical debt that had accumulated over the years.
Consequently, these teams must explore automated methods to deploy patches as swiftly as possible. DevSecOps teams may need to cope with continuous updates for multiple years as they deal with waves of patches. However, there will eventually be fewer issues to address, leading to a substantial improvement in overall application security.
Until then, DevSecOps teams might need to update applications continuously, which could become routine. The challenge lies in the fact that adversaries often create exploits faster than patches can be developed and applied. Moreover, adversaries are becoming proficient at using AI to combine low-level vulnerabilities into more potent exploits.
Consequently, DevSecOps teams may require virtual patches and other controls to counteract threats while waiting for AI-assisted patches. However, smaller open-source software project maintainers may struggle to keep pace due to limited resources. Multiple initiatives have been initiated to support these maintainers, but the primarily volunteer-based labor force may not have the time, resources, or motivation to develop, test, and implement patches promptly.
Enterprise IT organizations may need to reassess their open-source software deployment. While it may not be feasible to fix all applications before they are exploited, prioritizing updates to critical applications can at least mitigate potential damage.
Written by urgent.news from DevOps.com's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.