OSTIF Has Completed an Audit of Jetty!
- Post published:October 18, 2023
- Post category:Audits/Eclipse Foundation/Security/Trail of Bits
OSTIF is pleased to announce the completion of a security audit ofEclipse Jetty in collaboration with theEclipse Foundation andTrail of Bits. This audit was a part of a package of work organized and managed byOSTIF to provide security engagements to Eclipse Foundation projects. With funding and full support from the Foundation, OSTIF was able to provide three projects with much-needed security oversight, analysis, and recommendations that helps projects grow stronger and more secure than before.
In this particular case, Jetty was an excellent candidate for an audit. As a web/application server, the project handles data that can come from malicious sources, supports numerous protocols, and runs custom application code that is complex. Security of Jetty is imperative as the project is in applications run globally by millions. Audits like this are a great practice and routine to improve and harden open source projects’ security. Over time, audits help to locate vulnerabilities in code, fix issues that impact code health and security, and direct possible security work in the future to the most impactful locations.
The Eclipse Foundation is a frequent collaborator and funder of OSTIF, and when they wanted actionable, impactful security results for their money they came to us. OSTIF will always prioritize and seize any opportunity to work directly with open source projects to help improve their security and to engage high-quality security firms to do what they do best. As an organization, our sole focus is open source projects and their security and we get to perform our best work when we are backed by organizations who believe in our mission.
We would like to thank the Eclipse Foundation, specifically Jesse McConnell, Joakim Erdfelt, Mikael Barbero, and Marta Rybczynska for their aid in funding via theAlpha-Omega Project that made this endeavor possible. Further gratitude is extended to the team at Trail of Bits for their hard work and contributions to this audit, specifically Kelly Kaoudis, Spencer Michaels, Cliff Smith, and Sam Alws. Further thanks to Jeff Braswell as well.
Read the full report at:https://ostif.org/wp-content/uploads/2023/10/audit-of-eclipse-jetty-ostif-trail-of-bits-2023.pdf
Learn about the experience of the Eclipse Foundation at:https://mikael.barbero.tech/blog/post/2023-10-18-eclipse-jetty-security-audit-results/
More info about the experience for the Jetty team is available on the blog at:https://webtide.com/security-audit-with-trail-of-bits/
Topics
- ADA Logics
- Audits
- AWS
- Bug Bounties
- Chainguard
- CNCF
- Eclipse Foundation
- Encryption
- Financial
- Fundraiser
- Include Security
- Kudelski Security
- Linux Kernel
- Monero
- News
- Open Source
- OpenSSL
- OpenVPN
- QuarksLab
- Security
- Shielder
- Sovereign Tech Agency
- Sovereign Tech Agency
- Trail of Bits
- Transparency
- Unbound DNS
- Uncategorized
- VeraCrypt
- WireGuard
- X41-Dsec
Archives
Categories
- ADA Logics
- Audits
- AWS
- Bug Bounties
- Chainguard
- CNCF
- Eclipse Foundation
- Encryption
- Financial
- Fundraiser
- Include Security
- Kudelski Security
- Linux Kernel
- Monero
- News
- Open Source
- OpenSSL
- OpenVPN
- QuarksLab
- Security
- Shielder
- Sovereign Tech Agency
- Sovereign Tech Agency
- Trail of Bits
- Transparency
- Unbound DNS
- Uncategorized
- VeraCrypt
- WireGuard
- X41-Dsec
Archives
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- August 2022
- July 2022
- June 2022
- November 2021
- October 2021
- September 2021
- June 2021
- January 2021
- July 2020
- April 2020
- December 2019
- August 2019
- July 2019
- June 2019
- May 2019
- February 2019
- January 2019
- October 2018
- September 2018
- July 2018
- May 2018
- March 2018
- January 2018
- November 2017
- October 2017
- September 2017
- July 2017
- June 2017
- May 2017
- April 2017
- March 2017
- February 2017
- January 2017
- December 2016
- November 2016
- October 2016
- September 2016
- August 2016
- June 2016
- May 2016
- April 2016
- February 2016
- January 2016
- December 2015
- November 2015
- October 2015
- September 2015
- July 2015
- May 2015