Site navigation

Alarming Surge in High-risk Open Source Vulnerabilities

Michael Edgar

,

open source vulnerability
A new Synopsys report reveals an alarming surge in high-risk open source vulnerabilities.

The findings, unveiled in Synopsys’ ninth annual Open Source Security and Risk Analysis (OSSRA) report, expose a troubling escalation in high-risk vulnerabilities within commercial codebases.

Through looking at over 1,000 commercial database audits across 17 industries, the report paints a stark picture, where about three quarters (74%) of commercial codebases harbour open source components plagued by high-risk vulnerabilities, jumping from 48% the previous year. 

The data suggests instability and resource constraints might have contributed to the spike, as organisations grapple with intensified pressure to accelerate software development amid shrinking budgets.

“This year’s OSSRA report indicates an alarming rise in high-risk open source vulnerabilities across a variety of critical industries, leaving them at risk for exploitation by cybercriminals,” said Jason Schmitt, general manager at Synopsys Software Integrity Group. 

“The increasing pressure on software teams to move faster and do more with less in 2023 has likely contributed to this sharp rise in open source vulnerabilities. Malicious actors have taken note of this attack vector, so maintaining proper software hygiene by identifying, tracking and managing open source effectively is a key element to strengthening the security of the software supply chain.”

The report also unearthed a pervasive reliance on outdated or inactive open source components, with 91% of codebases containing components that were 10 or more versions behind. Nearly half (49%) of codebases featured components devoid of development activity over the past two years.


Recommended reading


The Computer Hardware and Semiconductors industry also emerged as the most vulnerable, with 88% of codebases housing high-risk open source vulnerabilities. Manufacturing, industrials, and robotics followed closely behind, with 87% of codebases affected. Even industries such as big data, AI, BI, and machine learning experienced significant vulnerability rates, with 66% of codebases impacted by high-risk vulnerabilities.

Licence compliance also remained a persistent challenge, with over half (53%) of codebases grappling with open source licence conflicts. Furthermore, 31% of codebases utilised code with either no discernible licence or a customised licence, potentially exposing organisations to legal and intellectual property risks.

FInally, eight of the top 10 vulnerabilities traced back to one common weakness type, which is classified as Improper Neutralisation weaknesses (CWE-707), encompassing various forms of cross-site scripting. This vulnerability type poses severe risks if exploited, underscoring the urgent need for comprehensive vulnerability management strategies.

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data