Are vulnerabilities discovered and resolved like other defects?

Patrick Morrison, Rahul Pandita, Xusheng Xiao, Ram Chillarege, Laurie Williams. Are vulnerabilities discovered and resolved like other defects?. Empirical Software Engineering, 23(3):1383-1421, 2018. [doi]

@article{MorrisonPXCW18,
  title = {Are vulnerabilities discovered and resolved like other defects?},
  author = {Patrick Morrison and Rahul Pandita and Xusheng Xiao and Ram Chillarege and Laurie Williams},
  year = {2018},
  doi = {10.1007/s10664-017-9541-1},
  url = {https://doi.org/10.1007/s10664-017-9541-1},
  researchr = {https://researchr.org/publication/MorrisonPXCW18},
  cites = {0},
  citedby = {0},
  journal = {Empirical Software Engineering},
  volume = {23},
  number = {3},
  pages = {1383-1421},
}