Technology Today

New research from RiskSense has revealed that the number of security vulnerabilities in open source software more than doubled last year.To compile its new report titled The Dark Reality of Open Source, the firm used data from 54 open source projects dating all the way back to 2015 until the first three months of 2020 to discover a total of 2,694 Common Vulnerabilities and Exposures (CVEs).RiskSense's report found the total number of vulnerabilities in open source software reached 968 last year which is up by more than 50 percent from the 421 CVEs found in 2018.
In a press release, CEO of RiskSense, Srinivas Mukkamala provided further insight on the report's findings, saying:While open source code is often considered more secure than commercial software since it undergoes crowdsourced reviews to find problems, this study illustrates that OSS vulnerabilities are on the rise and may be a blind spot for many organizations.
Since open source is used and reused everywhere today, when vulnerabilities are found, they can have incredibly far-reaching consequences.RiskSense's study also revealed how long it takes for open source software vulnerabilities to be added to the National Vulnerability Database (NVD).
On average it takes 54 days from a vulnerability being publicly disclosed for it to be included in the NVD.This delay has serious consequences for businesses as they can remain exposed to serious application security risks for almost two months.
These delays were also observed across all severities including vulnerabilities that were rated as critical and those that were being actively exploited in the wild.Of the open source projects analyzed in the report, the Jenkins automation server had the most CVEs overall with 646 and this was closely followed by MySQL with 624.
These two projects also tied for the most weaponized vulnerabilities with 15 each.When it came to weaponization, cross-site scripting (XSS) and Input Validation weaknesses were both some of the most common and most weaponized types of vulnerabilities in RiskSense's study.
XSS issues were the second most common type of vulnerability but they were the most weaponized while Input Validation issues were the third most common and second most weaponized.There are many benefits of using open source software though RiskSense's report shows that managing vulnerabilities in their libraries can pose unique challenges for businesses and developers.





Unlimited Portal Access + Monthly Magazine - 12 issues


Contribute US to Start Broadcasting - It's Voluntary!


ADVERTISE


Merchandise (Peace Series)

 


Spin Rewriter API is undergoing maintenance. Service will be restored later today at 9:30 AM EST. 2024-11-14 06:11:54


Spin Rewriter API is undergoing maintenance. Service will be restored later today at 9:30 AM EST. 2024-11-14 06:12:33


TopTech: Best of O2 Black Friday sale with simple way to cut ₤ 900 off Samsung phone


Sky dishes out blockbuster free TV upgrade that UK homes have been waiting for


Argos shoppers are grabbing Apple AirTags at 'lowest ever' price - don't miss out


Samsung Frame TV that can be used as art is now £400 cheaper in rare deal


DPD unveils robot courier that could potentially take on human delivery drivers


Nintendo's early Black Friday sale has £67 off Switch consoles in time for Christmas gift buying


Thousands of UK drivers warned to check their inbox now for worrying 'DVLA' email


Check your Sky TV box now or lose even more hugely popular channels this month


Unusual six-word Google search term which leaves you open to hackers is revealed


Get a PS5 disc drive and PS5 Pro for £636 with clever 20% discount tip at Very


Massive Gmail alert confirmed - check your inbox and delete these emails immediately


Check your postcode today or miss out on broadband and premium TV for free


Get two echo dots for the price of one in Amazon pre-Black Friday deal


Specialists alert to not Google these 6 words to safeguard yourself from hackers


Google puts all Android users on red alert - examine your phone to block 'severe' danger


Top Tech: Don't spend over the odds for an iPhone 14 Pro thanks to giffgaff deal


Samsung celebrates hit musical Wicked coming to UK big screen with epic sound system


Neglect Freeview, surprise Sky upgrade just made enjoying TV a lot more affordable


All you require to know for PS5 Pro as flagship brand-new console launches today


New Sky rival gets a more cost effective price and even lets you stream television totally free


Professionals caution of 'exceptionally severe' danger of cyber attacks to the UK


Millions of Windows 10 users face shock Microsoft fee, here's what it will cost you





54