Access and Feeds

Security: Open Source and Vulnerabilities

By Dick Weisinger

Open Source software and security. Are Open Source projects security focused and how nimble are they in addressing reported vulnerabilities?

With more than 300 projects, one of the biggest Open Source groups is the Apache Software Foundation (ASF). Apache software includes Hadoop, Tomcat, Kafka, Lucene, POI, and Zookeeper. The foundation publishes an annual report of security issues that have been reported and addressed for their software products.

The ASF report summarizes key metrics and reported vulnerabilities. Last year, 320 reports were made to ASF concerning software vulnerabilities.

ASF reported that “Apache Software Foundation projects are highly diverse and independent. They have different languages, communities, management, and security models. However one of the things every project has in common is a consistent process for how reported security issues are handled. This report gave metrics for calendar year 2019 showing from the 18,000 emails received we triaged over 300 vulnerability reports leading to fixing just over 100 (CVE) issues.”

Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
Google Buzz (aka. Google Reader)

Leave a Reply

Your email address will not be published. Required fields are marked *

*