2020-04-16 00:00:00

Security|Technologybug|Github|NVD|open source|report|software|vulnerability

Unsurprisingly, also open source software has vulnerabilities - here are some trends

Open source software products are often regarded safer and less vulnerable to malicious hacking than propriety software. The principle of showing the actual program code to the world and allowing other people and organizations to run the software is a valid method to discover potential problems. It is always a human who has written the code, however, and we all make mistakes.

Whitesource, an open source license management service, has put together a report that points out the scale of vulnerabilities in open source.

In March 2020, new reported vulnerabilities in open source software increased about 13% from February 2020. The total was 750 new reported cases in March according to the Whitesource report. While the number of discovered problems is not high, this is the amount of new vulnerabilities reported every month. Even with the 13% growth rate, it'll soon be considerably high.

Popular open source software management service Github hosts more than 100 million project repositories. No one knows how many software projects are developed on other services and on individual computers. In this perspective, the number of monthly discovered vulnerabilities is low, perhaps even too low.

The risk evaluation for vulnerabilities has remained relatively constant: 22% are critical, 36% high, 41% medium and 1% low risk problems. It means that the majority (58%) of bugs are in high risk category.

whitesource open source security vulnerability report: problem risk level ratio
Image: Whitesource report April Open Source Security Vulnerabilities Snapshot.

Cross-site scripting is the most common problem. Categorised as CWE-79 ( here is the detailed definition), it is about twice as common as the next two, CWE-200 and CWE-20, both related to interaction with users.

When the legendary computer company Sun introduced new programming language Java to the world more than 20 years ago, the key point that it is the secure tool for the internet era. Well, how about this: PHP, Java, Javascript and C are the four languages with most mentions in open source bug database. Probably this has something to do with the fact that they also happen to be the most used programming languages on the internet, but still.

Whitesource has compiled the monthly open source vulnerability report from NVD ( National Vulnerability Database - a U.S. initiative, but features problem reports from other parts of the world, also from Github) and other sources.

News

2025-05-14 16:03:00

Bordeaux is ready for hot summer days.#streetphotographyhttps://pixelfed.social/p/arihak/827854641319295061


Hochosterwitz castle

2025-05-10 15:23:05

Hochosterwitz castle


News

2025-05-07 14:39:00

A meeting in winter sun.#streetphotography #travelphotographyflic.kr/p/2qey2NHhttps://flic.kr/p/2qey2NH


News

2025-04-30 17:01:00

Shady character.#streetphotography #travelphotography #StreetPhotography


Not in space, but firmly on the ground in Valencia.

2025-04-25 17:47:30

arihak

Not in space, but firmly on the ground in Valencia.


News

2025-04-24 15:17:00

According to a survey, football (a sport where you are supposed to kick the ball instead touching the ball with a hand) is the most popular sports that fans want to follow live on site even if it means traveling overseas. #travelhttps://klaava.com/sports-events-are-trending-among-travelers/


News

2025-04-23 14:19:00

An unexpected recognition for analog #photography : UNESCO Cultural Heritage designation suggests a renewed appreciation for the craftsmanship and cultural significance of analog methods.https://www.diyphotography.net/analog-photography-recognized-as-intangible-cultural-heritage-by-unesco/


News

2025-04-17 13:18:00

New restriction on Flickr #photo sharing: Free #Flickr accounts will be restricted from downloading original and large-size images. While users will still be able to upload photos of all sizes, free account holders will only be able to download medium and small photos.https://petapixel.com/2025/04/16/flickr-restricting-download-sizes-for-free-accounts/


News

2025-04-16 10:54:00

Morning commute.#streetphotography#travelphotography


News

2025-04-12 09:17:00

The region in #Europe where you will get more #travel days for your euro (or whatever the local currency happens to be). The difference in the average cost is vast between the cheapest and the most expensive European countries.https://klaava.com/here-are-the-cheapest-countries-to-travel-in-europe/


Looks like a perfect spot for a cat to observe the street but no one was home when I passed the window.

2025-04-10 13:35:48

arihak

Looks like a perfect spot for a cat to observe the street but no one was home when I passed the window.


News

2025-04-07 08:50:00

When you take a #photo in RAW format the file is filled with extra data that allows for much richer post-processing, but the #camera world has never actually settled on one standardized RAW format.https://www.theverge.com/tech/640119/camera-raw-spec-format-explained-adobe-dng-canon-nikon-sony-fujifilm


News

2025-04-01 08:39:00

YouTube was the second-biggest media company in the world last year.And in 2025, #YouTube should eclipse #Disney, and become the biggest #media company in the world.https://www.businessinsider.nl/youtube-is-about-to-eclipse-disney-as-the-biggest-media-company-in-the-world/


News

2025-03-28 08:36:00

World Press Photo Contest 2025 ​have just been announced. This year, according to organizers, 59,320 images were submitted for judging, made by 3,778 photographers. #photographyhttps://www.theatlantic.com/photo/2025/03/winners-2025-world-press-photo-contest/682180/


Look around, and love your phone later

2025-03-22 10:17:39

arihak

Look around, and love your phone later


News

2025-03-21 12:50:00

An ancient football stadium?#streetphotography


News

2025-03-11 13:32:00

The World Photography Organisation has announced the category winners and shortlisted photographers for the Sony World #Photography Awards 2025 Open competition.https://www.dpreview.com/articles/0086546939/sony-world-photography-awards-2025-category-winners


News

2025-03-06 16:56:00

Coffee break.#streetphotography


News

2025-02-27 08:22:00

The Sony World #Photography Organisation unveiled the shortlisted entries and finalists in its annual competition’s 10 professional categories.https://edition.cnn.com/2025/02/25/style/sony-world-photography-awards-professional-2025/index.html


Summer heat.

2025-02-26 17:06:07

arihak

Summer heat.