OpenSSL
支撑全球HTTPS加密的开源基础库,2014年因Heartbleed漏洞暴露开源安全基础设施资金匮乏问题
Core Facts
Timeline (last 90 days)
2014年的Heartbleed漏洞(CVE-2014-0160)源于OpenSSL的TLS心跳扩展实现中的缓冲区过读错误,攻击者可每次读取服务器内存中最多64KB的数据
Heartbleed漏洞在OpenSSL代码中存在了超过两年才被发现,直接催生了Core Infrastructure Initiative(CII,后演变为OpenSSF)的成立
The 2014 Heartbleed vulnerability in OpenSSL exposed the dire funding situation of core open-source maintainers
在 2014 年 Heartbleed 漏洞爆出前,OpenSSL 核心维护者仅有一人,年度捐款不足两千美元
Heartbleed 漏洞事件直接催生了 Linux 基金会旗下的 Core Infrastructure Initiative(现为 OpenSSF)
2014年的Heartbleed漏洞揭示了OpenSSL这样被全球互联网依赖的项目仅由两名兼职维护者支撑
All Facts (6)
Heartbleed 漏洞事件直接催生了 Linux 基金会旗下的 Core Infrastructure Initiative(现为 OpenSSF)
65%Verified2014年的Heartbleed漏洞揭示了OpenSSL这样被全球互联网依赖的项目仅由两名兼职维护者支撑
65%UnverifiedThe 2014 Heartbleed vulnerability in OpenSSL exposed the dire funding situation of core open-source maintainers
85%Unverified2014年的Heartbleed漏洞(CVE-2014-0160)源于OpenSSL的TLS心跳扩展实现中的缓冲区过读错误,攻击者可每次读取服务器内存中最多64KB的数据
50%Unverified在 2014 年 Heartbleed 漏洞爆出前,OpenSSL 核心维护者仅有一人,年度捐款不足两千美元
50%UnverifiedHeartbleed漏洞在OpenSSL代码中存在了超过两年才被发现,直接催生了Core Infrastructure Initiative(CII,后演变为OpenSSF)的成立
50%