HomeSecurityFOSSA the EU funds bug bounty for 14 open source projects

FOSSA the EU funds bug bounty for 14 open source projects

FOSSA: The European Union will fund bug bounty programs for 14 open source projects, according to EU MEP Julia Reda.

FOSSA

The 14 projects are alphabetically the well-known applications:

7-zip, Apache Kafka, Apache Tomcat, Digital Signature Services (DSS), Drupal, Filezilla, FLUX TL, the GNU C Library (glibc), KeePass, midPoint, Notepad++, PuTTY, Symfony PHP framework, VLC Media Player, and WSO2.

Bug bounty programs (programs for finding errors in application code) are funded under the third edition of the Free and Open Source Software Audit (FOSSA) project.

EU authorities first approved FOSSA in 2015, after security researchers discovered serious vulnerabilities a year earlier in the OpenSSL library, an open source project that websites (and others) use to support HTTPS connections.

“The issue made many realize how important Free and Open Source Software is to the integrity and reliability of the Internet and other infrastructure,” Reda said in her statement.

Like many other organizations, institutions such as the European Parliament, the European Council, and the European Commission rely on Free Software to power their websites.

The first version of FOSSA was piloted between 2015 and 2016, with an initial budget of 1 million euros. The EU identified the most popular open source projects used by EU offices and employees and conducted a public survey to decide which ones to fund. Two projects were selected, the Apache web server and the KeePass password manager.

FOSSA 2 was launched in 2017 as a HackerOne bug bounty for the VLC Media Player application. The project received funding of 2 million euros.

Now, FOSSA is back for its third edition with budgets for 14 bug bounty programs. The highest budgets are for the PuTTY application and the Drupal CMS web application.

SoftwareFinancingInceptionExpiryBug Bounty Platform
Filezilla58.000,00 €07/01/201915/08/2019HackerOne
Apache Kafka58.000,00 €07/01/201915/08/2019HackerOne
Notepad++71.000,00 €07/01/201915/08/2019HackerOne
PuTTY90.000,00 €07/01/201915/12/2019HackerOne
VLC Media Player58.000,00 €07/01/201915/08/2019HackerOne
FLUX TL34.000,00 €15/01/201915/10/2019Integrity/Deloitte
KeePass71.000,00 €15/01/201931/07/2019Integrity/Deloitte
7 zip58.000,00 €30/01/201915/04/2020Integrity/Deloitte
Digital Signature Services (DSS)25.000,00 €30/01/201915/10/2019Integrity/Deloitte
Drupal89.000,00 €30/01/201915/10/2020Integrity/Deloitte
GNU C Library (glibc)45.000,00 €30/01/201915/12/2019Integrity/Deloitte
PHP Symfony39.000,00 €30/01/201915/10/2019Integrity/Deloitte
Apache Tomcat39.000,00 €30/01/201915/10/2019Integrity/Deloitte
WSO258.000,00 €30/01/201915/04/2020Integrity/Deloitte
midPoint58.000,00 €01/03/201915/08/2019HackerOne

So, starting in January, researchers and security companies can hunt for vulnerabilities in the above open source projects. By reporting potential vulnerabilities (bugs) in the applications listed above, they will be able to earn financial rewards from the EU, provided that the errors they discover are critical.

__________________

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS