Access and Feeds

Open Source: As Adoption Grows so Does the List of Known Vulnerabilities

By Dick Weisinger

The number of vulnerabilities identified in Open Source software projects nearly increased by 50 percent in 2019, according to a study by White Source Software.

White Source Software: Open Source Vulnerability Management Report

What’s causing the rapid discovery of security issues? It seems to be primarily visibility. Open Source software is setting ever greater adoption rates and there are simply more eyes on Open Source software.

The majority of security flaws identified in 2019 were the result of cross-site scripting, improper input validation, buffer errors, out-of-bounds reads, and information exposure.

The report from White Source finds value in centralizing the handling of bug reporting and the posting of fixes. This kind of “institutional awareness” about managing security is key into improving security. Microsoft’s GitHub, for example, now allows developers and maintainers to report security vulnerabilities and published fixes to the problems in a central location.

The White Source report concludes that tThe most important takeaway is that just because popular open source projects have vulnerabilities, that doesn’t mean they are inherently insecure. It only means that as a user of open source projects you need to be aware of the security risks and make sure to keep your open source dependencies up to date.”

Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
Google Buzz (aka. Google Reader)

Leave a Reply

Your email address will not be published. Required fields are marked *

*