CISA Vulnerability Review flags vulnerabilities in open-source software

The CISA Vulnerability Review identified gaps in publicly available vulnerability data and common weaknesses in software, including Apache Kafka, OpenShift, and OpenSSL.

Bottom line: CISA urges organizations to address the root causes of vulnerabilities in open-source software.

What's happening: The review examined data from the National Vulnerability Database (NVD) and identified 74,000 missing vulnerability reports for open-source software, including Apache Kafka, OpenShift, and OpenSSL. The review also found that 25% of NVD entries are from 2016 or earlier, with an average CVSS score of 4.4. CISA is urging vendors to improve their vulnerability reporting, with a focus on Secure by Design principles.

What to do: CISOs and security leaders should review their vulnerability management processes to ensure they address the root causes of vulnerabilities in open-source software, and prioritize Secure by Design principles when evaluating software and vendors.

Source: Industrial Cyber