Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Growing Open Source Use Heightens Enterprise Security Risks
Newest First  |  Oldest First  |  Threaded View
<<   <   Page 2 / 2
Neta1
Neta1,
User Rank: Apprentice
1/26/2015 | 9:13:48 AM
WhiteSource proves that open source is safe if used responsibly
WhiteSource has been helping companies of all sizes to responsibly and effortlessly manage the open source components they use.

We've been doing it since 2011 and for all programming languages, we are in a unique position to look at real data from a large number of commercial projects.

Our research shows that if managed properly - ie updated when new security vulnerabilities are disclosed or when new versions are available - 98% of the projects that contain faulty open source components would not contain them. 

So the problem is not open source but how it is used.
Joe Stanganelli
Joe Stanganelli,
User Rank: Ninja
1/25/2015 | 8:25:25 PM
Frankenstein
Hah!  I <3 the Frankenstein analogy!

This is the folly of Linus's Law -- i.e., "Given enough eyeballs, all bugs are shallow."

Akamai's CSO, Andy Ellis, put it best at a cybersecurity conference I attended a couple months back: "The Florida Everglades happen to be shallow as well.  It's still a swamp!"
KennonK748
KennonK748,
User Rank: Apprentice
1/25/2015 | 1:58:41 PM
blast from the past
Wow it's like this article was caught in a time warp and just appeared 10-15 years after it was written and somehow got published. So the parking websites were hacked because they were using open source software?!?! I love this line "victimized by a security vulnerability in the Joomla open-source content management platform for which a patch had been issued last September, but which neither company had apparently installed."


They were victimized because they didn't patch software. It has nothing to do with the source code being open or closed. It could have been unpatched IIS or anything else. Hello, 1998 called and they would like their tech story back.
<<   <   Page 2 / 2


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The Promise and Reality of Cloud Security
Cloud security has been part of the cybersecurity conversation for years but has been on the sidelines for most enterprises. The shift to remote work during the COVID-19 pandemic and digital transformation projects have moved cloud infrastructure front-and-center as enterprises address the associated security risks. This report - a compilation of cutting-edge Black Hat research, in-depth Omdia analysis, and comprehensive Dark Reading reporting - explores how cloud security is rapidly evolving.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-10075
PUBLISHED: 2023-02-07
A vulnerability was found in Custom-Content-Width 1.0. It has been declared as problematic. Affected by this vulnerability is the function override_content_width/register_settings of the file custom-content-width.php. The manipulation leads to cross site scripting. The attack can be launched remotel...
CVE-2022-21948
PUBLISHED: 2023-02-07
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in paste allows remote attackers to place Javascript into SVG files. This issue affects: openSUSE paste paste version b57b9f87e303a3db9465776e657378e96845493b and prior versions.
CVE-2015-10074
PUBLISHED: 2023-02-07
A vulnerability was found in OpenSeaMap online_chart 1.2. It has been classified as problematic. Affected is the function init of the file index.php. The manipulation of the argument mtext leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version staging is ab...
CVE-2022-31254
PUBLISHED: 2023-02-07
A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Server for SAP 15-SP1, SUSE Manager Server 4.1; openSUSE Leap 15.3, openSUSE Leap 15.4 allows local attackers with access to the _rmt user to escalate to r...
CVE-2023-0706
PUBLISHED: 2023-02-07
A vulnerability, which was classified as critical, has been found in SourceCodester Medical Certificate Generator App 1.0. Affected by this issue is some unknown functionality of the file manage_record.php. The manipulation of the argument id leads to sql injection. The attack may be launched remote...