Bottom line: CISA urges organizations to address the root causes of vulnerabilities in open-source software.
What's happening: The review examined data from the National Vulnerability Database (NVD) and identified 74,000 missing vulnerability reports for open-source software, including Apache Kafka, OpenShift, and OpenSSL. The review also found that 25% of NVD entries are from 2016 or earlier, with an average CVSS score of 4.4. CISA is urging vendors to improve their vulnerability reporting, with a focus on Secure by Design principles.
What to do: CISOs and security leaders should review their vulnerability management processes to ensure they address the root causes of vulnerabilities in open-source software, and prioritize Secure by Design principles when evaluating software and vendors.