Understanding and combating open source software vulnerabilities
> Who am i
2
@harekrishnarai
START
Agenda
3
START
What is Open source vulnerabilities?
4
START
Open source vulnerabilities
Open source vulnerabilities are security flaws or weaknesses found in open-source software components, such as libraries, frameworks, or applications.
These vulnerabilities can occur due to coding errors, outdated versions, or misconfigurations and are publicly available for both developers and attackers to exploit.
5
START
Dependencies of an Open source project
Some stats about Open Source Vulnerabilities
Source - Internet
A
Statistics on Open Source Vulnerabilities
70% of applications use at least one vulnerable open-source component.
50% of all vulnerabilities found in applications come from open-source libraries.
43% of vulnerabilities are due to indirect dependencies in open-source code
85% of vulnerabilities in open source can be fixed with a library upgrade.
B
55%
35%
10%
Exploitability of open-source vulnerabilities
source: Internet
START
8
Demo Time
START
Types of Scanning OSS packages vuln
9
START
Example - Manifest Scanning�
10
START
Reachability Scanning
11
START
Role of EPSS in combating OSS vuln
12
source: Internet
START
What’s next?
13
START
References
14
START
15
Mujhe break lena hai
START
Thank you
16
START