Only 3% of Open Source Software Bugs Are Actually Attackable, Researchers Say

General News

Summary

The data implies that if application security (appsec) pros and developers work to focus on fixing and mitigating whats truly attackable, they could drastically reduce the strain on their teams. Data from the report shows that developers saw a 97% reduction in false-positive library upgrade tickets once they considered attackability when examining packages in use with critically rated vulnerabilities. When a new high-profile supply chain vulnerability like Log4Shell or Spring4Shell hits the industry back channels, then blows up into the media headlines, their teams are called to pull long days and nights figuring out where these flaws impact their application portfolios, and even longer hours in applying fixes and mitigations to minimize risk exposures. "So the fundamental premise of the report makes total sense, but what we have also learned from interviews is that answering that question is very hard and more complex than am I using a particular bit of code," Curphey says. Finally, Magill says security leaders need to remember that many threats exist to software supply chains beyond the normal churn of bugs that are found incidentally within open source projects.

Classifications

industries
No industries detected
applications
Search and Information retrieval

AskAI Classifications

Labels
No AI classifications detected

Linked Companies

Qwiet
$5M to $10M