Technology Today

New research from RiskSense has revealed that the number of security vulnerabilities in open source software more than doubled last year.To compile its new report titled The Dark Reality of Open Source, the firm used data from 54 open source projects dating all the way back to 2015 until the first three months of 2020 to discover a total of 2,694 Common Vulnerabilities and Exposures (CVEs).RiskSense's report found the total number of vulnerabilities in open source software reached 968 last year which is up by more than 50 percent from the 421 CVEs found in 2018.
In a press release, CEO of RiskSense, Srinivas Mukkamala provided further insight on the report's findings, saying:While open source code is often considered more secure than commercial software since it undergoes crowdsourced reviews to find problems, this study illustrates that OSS vulnerabilities are on the rise and may be a blind spot for many organizations.
Since open source is used and reused everywhere today, when vulnerabilities are found, they can have incredibly far-reaching consequences.RiskSense's study also revealed how long it takes for open source software vulnerabilities to be added to the National Vulnerability Database (NVD).
On average it takes 54 days from a vulnerability being publicly disclosed for it to be included in the NVD.This delay has serious consequences for businesses as they can remain exposed to serious application security risks for almost two months.
These delays were also observed across all severities including vulnerabilities that were rated as critical and those that were being actively exploited in the wild.Of the open source projects analyzed in the report, the Jenkins automation server had the most CVEs overall with 646 and this was closely followed by MySQL with 624.
These two projects also tied for the most weaponized vulnerabilities with 15 each.When it came to weaponization, cross-site scripting (XSS) and Input Validation weaknesses were both some of the most common and most weaponized types of vulnerabilities in RiskSense's study.
XSS issues were the second most common type of vulnerability but they were the most weaponized while Input Validation issues were the third most common and second most weaponized.There are many benefits of using open source software though RiskSense's report shows that managing vulnerabilities in their libraries can pose unique challenges for businesses and developers.





Unlimited Portal Access + Monthly Magazine - 12 issues


Contribute US to Start Broadcasting - It's Voluntary!


ADVERTISE


Merchandise (Peace Series)

 


Top Tech: Amazon's best early Prime Day deals including Ring, Tefal and Nespresso


Brits now 'obsessed' with health tracking and say it's key to motivation


Virgin Media is distributing complimentary wise TVs in surprise seven-day sale


O2 confirms UK network switch off and the exact date your phone might quit working


Samsung and Google have a new Android competitor that's like Nothing you've seen before


'Spectacular' Samsung Galaxy S25 Ultra gets £10 a month price cut


Sky users given 48-hour cost alert and your costs could increase tomorrow


Never ever miss your favourite television series when on vacation with basic travel hack


Amazon may offer big reason to ditch your Fire TV Stick next week and try something new


Samsung and Google smartphone deals consist of free earbuds and smartwatches


Everyone using Google Chrome must restart their browser now - don't ignore new alert


iPhone users surprised after finding 'concealed' hack to organise home screen


Sky dishes out brand-new iPhone 16 at 'lowest ever' rate, not surprising that it's offering fast


Argos shoppers can get a free 40-inch Hisense TV by doing one thing


Immediate alert for everyone with a Gmail account - do not overlook 6 important brand-new rules


BBC iPlayer is rivalling Sky TV with a vital free upgrade - check your settings now