The most popular and comprehensive Open Source ECM platform
Security: Open Source and Vulnerabilities
Open Source software and security. Are Open Source projects security focused and how nimble are they in addressing reported vulnerabilities?
With more than 300 projects, one of the biggest Open Source groups is the Apache Software Foundation (ASF). Apache software includes Hadoop, Tomcat, Kafka, Lucene, POI, and Zookeeper. The foundation publishes an annual report of security issues that have been reported and addressed for their software products.
The ASF report summarizes key metrics and reported vulnerabilities. Last year, 320 reports were made to ASF concerning software vulnerabilities.
ASF reported that “Apache Software Foundation projects are highly diverse and independent. They have different languages, communities, management, and security models. However one of the things every project has in common is a consistent process for how reported security issues are handled. This report gave metrics for calendar year 2019 showing from the 18,000 emails received we triaged over 300 vulnerability reports leading to fixing just over 100 (CVE) issues.”













