Vulnerabilities in open source sometimes go unnoticed for more than 4 years

Security vulnerabilities in open-source software sometimes go undetected for more than four years. This is one of the key findings of the latest State of the Octoverse report from the software development hosting and management platform GitHub.

However, this statement is not entirely true, since, based on technological advancements and the fact that in recent years many large companies and developers have joined the open source software movement, this has allowed for increasingly rapid progress in terms of development, creation of testing tools, and especially vulnerability detection.

Although it is still a reality, insufficient funding (which leads to a reduction in human resources) is most often an obstacle to the search and discovery of these vulnerabilities.

Heartbleed, for example, is a software vulnerability present in the OpenSSL cryptography library since March 2012. It allows an attacker to read the memory of a server or client to retrieve data used during Transport Layer Security (TLS) communication. The flaw, which affects many internet services, wasn't discovered until March 2014 and was made public in April 2014. This left a two-year window for hackers to attack thousands of servers.

The vulnerability supposedly ended up in the OpenSSL repository by mistake following a proposal from a volunteer developer to fix bugs and improve features.

These types of flaws (introduced by mistake) account for 83% of those discovered in open-source projects hosted on GitHub. However, the latest State of the Octoverse report states that 17% are vulnerabilities intentionally introduced by malicious third parties.

These are figures that should be supplemented by a recent Risksense report that emphasizes that flaws in open source software are constantly growing. IT projects are increasingly based on open source, which explains the growing interest of hackers in the field.

A vulnerability can wreak havoc on your work and cause large-scale security problems. However, most vulnerabilities are due to bugs, not malicious attacks.

By relying on open source when you can, your team benefits from all the fixes found and remediated by the community. Time to remediate is an important component for all DevOps teams

The funding model for the open-source sphere is among the factors most likely to explain why software vulnerabilities often go undetected during critical times. The Core Infrastructure Initiative (CII) is one of the few projects that fund and support free and open-source software projects essential to the functioning of the internet and other large information systems.

Most of the projects on GitHub are based on open source software. This analysis included open source public repositories with at least one contribution in each month between 10.1.2019 and 30.09.2020.

The latter has been the subject of an announcement following the critical Heartbleed vulnerability in OpenSSL that is used by millions of websites. Problem: CII relies on contributions from well-established players in the world of proprietary software. Facebook, VMWare, Microsoft, Comcast, and Oracle (to name just these companies) fund the Linux Foundation, and thus projects like the Central Infrastructure Initiative (CII).

This gives them seats on the various decision-making boards, and therefore some control over what happens in the open source arena. Bryan Lunduke, a former openSUSE Board member, discusses this state of affairs in more detail.

The immediate consequence is that the open source projects that benefit from funding are those on which their infrastructures are primarily based.

Finally, if you are interested in learning more about this , you can consult the following website where you can find the compiled reports.

The link is this.


Add as preferred source in Google