Up to 60% of all code used in enterprises contains at least one vulnerability that comes from open source, according to new research.

On Tuesday, Black Duck by Synopsys published its annual Security and Risk Analysis (OSSRA) report, in which it analyzed the anonymized data of 1,200 commercial source codes from 2018.
Open source software, libraries, and other additional pieces of code are of great importance to businesses today.
With the support of the open source community, many talented developers are willing to contribute to projects, program by sharing their code, and achieve faster system development times. All of the above contribute to achieving high open source adoption rates.
Of all the source code reviewed by Black Duck, 96% contained open source code, and most source code without open source contributions contained fewer than 1,000 files. If the number is revised to sources with more than 1,000 files, the open source adoption rate increases to 99%.
On average, Black Duck identified 298 open source points per source in 2018, compared to 257 the previous year.
While the benefit of open source in a project can mean that open source has security advantages, sometimes, vulnerabilities can be shared over the network or remain dormant, as developers may not realize they are affected by a security flaw.
Of the code sources examined, 60% contained at least one vulnerability. However, the situation appears to be improving, as this is down from 78% in 2017.
Overall, Black Duck reports that over 40% contained vulnerabilities that were deemed critical.
“The reality is that open-source is no less secure than proprietary code,” the report says. “But it’s no more secure either. All software, whether proprietary or open, has weaknesses that can become vulnerabilities, which companies need to identify and fix.”.
The average age of vulnerability detection was 6.6 years. The oldest, CVE-2000-0388, is a buffer overflow flaw in the FreeBSD libmytinfo library that was discovered 28 years ago. Overall, 43% of scanned source code contained a bug that was more than 10 years old, which may indicate that companies are unaware of how their open source code is being used or what it contains, leaving the software unmodified and open to exploitation.
“Only a few open source vulnerabilities – such as those affecting Apache Struts or OpenSSL – are likely to be widely exploited,” the researchers say. “With that in mind, companies should focus their efforts on managing open source vulnerabilities and mitigating their impact.”.
