370+ Companies Report Open Source Breaches in Past 12 Months

Over 370 Organizations Report Confirmed or Suspected Open Source Breaches in Past 12 Months According to Sonatype Survey

Survey Finds 75 Percent Put Consumers at Risk with Poor Software Component Control

FULTON, MD (July 22, 2014)– Three out of four organizations that build software applications either have failed to adopt policies to prevent the use of vulnerable software components or have neglected to ban even a single component to enforce existing policies, according to a new survey sponsored by venture capital firm New Enterprise Associates, Inc. (NEA) and software supply chain management company Sonatype. In the survey 3 out of 10 respondents actually admitted they either had or suspect a breach was caused by an open source component within the last 12 months.

The 2014 State of Open Source Development and Application Security Survey questioned more than 3,300 software developers, architects and application security professionals around the world about their use of open source software, policies governing its use, and common application security practices.

The survey provides a clear perspective on the state of application security across many of the world’s leading software development organizations because 90 percent of a typical application is composed of open source components, with more than 13 billion requests served for these free, reusable software building blocks last year. Among the survey highlights:

As with any software, flaws will be found in open source components. But unlike internally developed software code, organizations bringing open source components into their firms do not have effective governance policies and practices to identify, track or remediate vulnerabilities within those components. This creates a rich target for hackers to exploit the vulnerable applications.

“Applications are the #1 attack vector leading to breaches, according to the 2014 Annual Verizon Data Breach Investigations Report. That means that if you are not using secure components, you are not building secure applications,” said Wayne Jackson, CEO of Sonatype. “Our survey clearly shows that most companies completely ignore the problem, and this creates an extraordinary security risk, as the panic over the Heartbleed bug demonstrated. This isn’t a theoretical threat. It’s real, and some very large businesses have admitted to being attacked.”

In fact, according to a Sonatype analysis, in one year there were more than 46 million requests for insecure versions of the 31 most popular open source security libraries. And even after critical or severe vulnerabilities were announced and fixed in these popular open source components the vulnerable versions continue to be downloaded on a massive scale: Struts2 web application framework (179,050 downloads), the Bouncy Castle cryptography API (214,484 downloads), the Jetty web application server (5,174,913 downloads) and the HTTP Client implementation for Java (3,749,193 downloads).

Sonatype recommends that application developers avoid use of flawed components by using software offering automated governance, monitoring and alerts to identify and proactively fix component vulnerabilities throughout the software development lifecycle.

The 2014 State of Open Source Development and Security Survey was co-sponsored by Contrast Security, Rugged Software and the Trusted Software Alliance. It marked the fourth annual examination of open source software development trends spearheaded by Sonatype to raise awareness and improve development and security practices. Full survey results can be found at www.sonatype.com/company.