Posted in

Open Source Vulnerability Management: Be Wise Prioritize

A digital illustration of cracked infrastructure pipes leaking data from a central box labeled MCP Server, with shadowy figures exploiting the leaks next to text reading CVSS 9.8.
The hidden risk of agentic AI: Recent structural flaws in Model Context Protocol (MCP) implementations have introduced critical CVSS 9.8 attack surfaces.

It’s safe to say that open source has made it to the big leagues. Across all industries, from healthcare to fintech to IoT and everything in between, software organizations of every size are harnessing the power of open source components to create their innovations. While open source components provide developers with a powerful tool for building better software faster, They also present them with a new set of challenges, the first one being open source security.

In a recent Open Source Vulnerability Management Report for 2018, found that open source vulnerabilities rose by over 60% over the past 18 months, challenging developers to keep up with maintaining their product’s security. So have they been up to the task? It is interesting to understand how developers are contending with this increasing workload, all without slowing down their DevOps cycle.

Developers Are Worried About Open Source Vulnerabilities

To gain insight into the way developers today are facing the challenge of open source security, a survey was conducted among over 650 software developers in North America and Eastern Europe and received back some very interesting results.

Developers are well aware of the severe threat of open source vulnerabilities, with 26% of respondents rating security vulnerabilities as their top challenge when dealing with open source. Security concerns ranked above other challenging open source component issues like integration, functionality, licensing and selection.

Clocking In: How Much Time Does Vulnerability Management Demand?

Survey results show that the concern over open source vulnerabilities takes up quite a chunk out of developers’ time. Respondents said that they invest nearly 15 hours every month dealing with open source security vulnerabilities. Usually, the more experienced developers are the ones handling this task, which makes this investment even more costly.

Unfortunately, developers only dedicate a fraction of those 15 monthly hours on remediation, which respondents said they spent only 3.8 hours each month. The rest of the 15 monthly hours go towards other tasks related to dealing with open source vulnerabilities, like reviewing the vulnerabilities discovered in software projects, as well as discussing, addressing, and remediating them.

Looking at these results, we couldn’t help but wonder whether developers are making the best use of their time where open source vulnerabilities are concerned.

So Many Remediation Processes, So Little Time

Although developers are very concerned about open source security and admit to investing a lot of their time attending to vulnerabilities, their answers to questions regarding their processes for dealing with open source vulnerabilities were inconsistent.

It seems that currently there is no standard practice across software development organizations when it comes to addressing open source vulnerabilities. Developers were evenly divided when it came to their course of action when dealing with open source vulnerabilities. Methods included researching the vulnerability, reporting it to a manager or another team like security or DevOps, remediation via a patch, or remediation based on the open source community’s recommendations.

These varied responses are most probably a result of giving developers the responsibility without providing them with the right tools or processes needed for the task of open source security management. Developers usually aren’t familiar with the code in their open source components, or with the many transitive dependencies involved in open source libraries. How can they be expected to know where to start when it comes to remediating open source vulnerabilities?

Open Source Vulnerability Management: Prioritize Much?

The exponential rise in security vulnerabilities over the past few years, along with heightened awareness of the importance of swift remediation, have resulted in development teams drowning under a surge of security alerts, including those involving open source vulnerabilities.

Industry experts agree that attempting to solve every single issue is impossible, and that prioritization is key to vulnerability management. Neil MacDonald of Gartner, stresses the need to, bring continuous risk and trust-based assessment and prioritization of application vulnerabilities to DevSecOps.

According to MacDonald, attempting to address all vulnerabilities, only leads to slowing developers down and wasting their time chasing issues that aren’t real (false positives) or addressing lower-risk vulnerabilities that are real, but not directly or easily exploitable.

Open Source Vulnerability Prioritization: What Goes First?

One of the main problems that arises from the survey results is that there is no agreed upon best practice for prioritization of open source vulnerability remediation.

According to our survey, the decision to prioritize remediation of open source vulnerabilities might be based on any number of parameters, including the criticality of the impacted project, the availability of suggested fixes, the number of libraries containing the vulnerability, criticality based on CVSS score, or creation date of the vulnerability alert.

Development teams prioritize based on the data most easily available to them, but none of these parameters is necessarily indicative of how a vulnerability actually impacts a particular project, which should be the driving factor behind how they plot their course of action. This leaves development teams bogged down in an endless flow of security alerts with no way to objectively sort through the noise to get to the most critical vulnerabilities first.

We argue that what is needed is evidence-based decision-making practices that can be standardized across teams, offering everyone a common open source security strategy of how to make remediation ops workable.

Vulnerability Prioritization: A Winning Strategy

Open source components are considered to compromise between 60-80% of the code base in modern applications. So considering the number of open source vulnerabilities published each month, organizations that learn how to best prioritize remediation of open source security vulnerabilities can crack the code to efficient and secure open source management.

In the race against hackers, time is of the essence, especially when it comes to open source vulnerabilities where data is public. Currently, the lack of standard open source management processes as well as dedicated tools leads many development teams to inefficiently use their resources, spending a lot of time sorting through open source vulnerability alerts and attending to those that aren’t necessarily the most critical.

Organizations that adopt the automated tools to manage and address open source vulnerabilities will save their developers a lot of time and ensure that they are dealing with the burning issues without being bogged down by hundreds of security alerts.

Rami Sass is CEO and Co-Founder of WhiteSource , the leading open source security and compliance management platform. Rami is an experienced entrepreneur and executive with vast experience in defining innovative products, leading technology groups and growing companies from seed level to business maturity.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.