$4.99/mo - Save 61% With Exclusive 2-Year Plan + 4 Months Free!Claim Now

Organizations Struggle with Open-Source Dependency Management Amid Rising Vulnerabilities

  • Last updated November 6, 2024
  • written by
    Writer

City, November 6, 2024 – A recent report highlights that most organizations are still immature in managing open-source software (OSS) dependencies, which could lead to significant cybersecurity vulnerabilities. The findings emphasize the urgent need for better strategies to handle these risks as software supply chain attacks become more prevalent.

As open-source software gains widespread adoption, the reliance on external code and libraries has increased, creating a complex landscape for cybersecurity professionals. Despite the growing awareness of the risks associated with OSS, many organizations lack effective processes for identifying and prioritizing vulnerabilities in their dependencies.

The Endor Labs “State of Dependency Management Report” for 2024 provides critical insights into the challenges faced by organizations in managing OSS dependencies. The report indicates that most organizations struggle to recognize and address the vulnerabilities associated with third-party libraries and frameworks, which are essential for software functionality.

One of the key issues identified is the reliance on outdated methods, such as the Common Vulnerability Scoring System (CVSS), which often leads to inefficient use of resources. The report advocates for a context-driven approach to vulnerability management, leveraging resources like CISA’s Known Exploited Vulnerabilities (KEV) catalog and the Exploit Prediction Scoring System (EPSS) to prioritize remediation efforts effectively.

Additionally, the report notes that fewer than 9.5% of vulnerabilities are exploitable at the function level, and organizations that integrate reachability analysis with EPSS can achieve a 98% reduction in noise during vulnerability management. This highlights the importance of focusing on actual risks rather than merely following traditional vulnerability scoring systems.

However, the report underscores a significant challenge with the National Vulnerability Database (NVD), which has been struggling to provide timely and enriched data on vulnerabilities. With over 18,000 unenriched CVEs reported and an enrichment rate of less than 50%, the NVD’s inefficiencies complicate the vulnerability management landscape for organizations.

Moreover, the report reveals that it takes an average of 25 days for public vulnerability databases to publish advisories after a patch is available, and many advisories lack crucial details about specific vulnerabilities. This delay can expose organizations to active exploitation attempts soon after vulnerabilities are discovered.

In conclusion, the Endor Labs report emphasizes the urgent need for organizations to adopt more effective dependency management strategies to mitigate the risks associated with open-source software. By prioritizing vulnerabilities based on actual risk and enhancing their vulnerability management processes, organizations can better protect themselves against the growing threat of cyberattacks.