phpBB Heb

Main Menu

  • Home
  • Internet Forum
  • PHP Scripting Language
  • Open Source Software
  • Online Communities
  • Commerce

phpBB Heb

Header Banner

phpBB Heb

  • Home
  • Internet Forum
  • PHP Scripting Language
  • Open Source Software
  • Online Communities
  • Commerce
Open Source Software
Home›Open Source Software›Apache Software Foundation warns that its patching efforts are undermined by the use of end-of-life software

Apache Software Foundation warns that its patching efforts are undermined by the use of end-of-life software

By George T. Sprague
January 14, 2022
0
0

Adam Bannister January 14, 2022 at 15:01 UTC

Updated: January 14, 2022 15:05 UTC

The nonprofit shares metrics in its latest annual security review of more than 350 projects

The Apache Software Foundation (ASF) has warned that its efforts to respond quickly to security vulnerabilities are being undermined by organizations running end-of-life versions of Apache software.

The warning came amid ASF’s latest annual review of security in the Apache ecosystem, which found the nonprofit received 441 reports of potential new vulnerabilities in 2021 across 99 Apache projects. high level.

This figure represents a 17% increase in submissions reaching triage compared to 2020 (376 reports) and 38% compared to 2019 (320).

Yard firewall

The reports ultimately accounted for 183 CVEs – up 21% from 2020 (151) and 50% from 2019 (122) – which included the explosive Log4j vulnerability in December and a number of other flaws affecting multiple projects.

Fifty of the 441 reports, sent by both project managers and external security researchers, were still being triaged at the end of the year, meaning they had not yet received a CVE or rejected as invalid. That number was higher than expected due to an increase in reports in late December, the ASF said.

RELATED “Being serious about safety is a must” – ASF custodians on fulfilling its founding mission

“While the ASF often gets updates quickly for critical issues, reports show that users are being exploited by old ASF software issues that haven’t been updated in years, and vendors (and therefore their users) are still using end-of-the-line versions that have known unpatched vulnerabilities,” said Mark Cox, vice president of security for ASF.

“This will continue to be a big issue and we are committed to tackling this industry-wide issue to determine what we can do to help.”

White House Summit

That supply chain weaknesses lie downstream and upstream was one of the points raised by the ASF in a position paper released ahead of its participation yesterday (January 13) in a virtual summit hosted by the House White and focused on open source security.

The ASF said it also received 135 emails reporting “flaws” on Apache’s website in 2021, nearly all of which were “false positives.”

The ASF report highlighted other notable Apache vulnerabilities and developments in 2021, unsurprisingly, this included the notorious Log4j bug.

RECOMMENDED Security Done Right: Celebrating Infosec Victories in 2021

He also reported a cross-site scripting (XSS) flaw in Apache Velocity that was prematurely disclosed in January after a delay of several months between the development of a patch and the release of the corresponding patch.

ASF welcomed research into new HTTP/2 proprietary threats affecting Apache HTTP Server (CVE-2021-33193) published in August, and the addition of Apache Airflow, Apache HTTP Server, and Apache Commons to HackerOne’s Internet Bug Bounty program in October. .

Despite the resource constraints inherent in a volunteer organization, Mark Cox said the ASF continues to build “a consistent process for how reported security issues are handled” across more than 350 diverse Apache projects and independent, and reserves the right to archive projects that fail.

DON’T FORGET TO READ Bug Alert launched to provide an early warning system for super critical vulnerabilities

Related posts:

  1. Eclipse Sparkplug working group continues to drive adoption of IIot specifications – ADTmag
  2. Armory uses K3 to simplify CD Spinnaker installations
  3. IBM moves to ‘container native’ with software-defined storage platform for OpenShift, Cloud Native
  4. Opto 22 joins the Eclipse Foundation and the Sparkplug working group
Tagshigh levelvice president

Recent Posts

  • A high country paradise for sockeye salmon | Alaska Science Forum
  • How to Choose the Best Tech Stack for Your Startup in 2022
  • Open Source to commercial software, the process from project to product
  • 5G services expected to be rolled out within a month, says MoS Telecom
  • 3 ways every business can get started with an open source software strategy

Archives

  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020

Categories

  • Commerce
  • Internet Forum
  • Online Communities
  • Open Source Software
  • PHP Scripting Language
  • Terms and Conditions
  • Privacy Policy