Devs spanked for touching vulnerable open-source packages

Posted by Scott_Ruecker on Mar 27, 2012 6:29 PM EDT
The Register; By Gavin Clarke
Mail this story
Print this story

Developers are sucking buggy open-source programming frameworks off the web unaware that newer fixed versions exist, according to a new report. Packages of the Google Web Toolkit, the Spring Model View Controller, and Apache's Struts and Xerces have been downloaded millions of times despite the fact they contain known vulnerabilities - as evidenced by a trawl through the Sonatype.org central repository.

Full Story

  Nav
» Read more about: Story Type: News Story

« Return to the newswire homepage

This topic does not have any threads posted yet!

You cannot post until you login.