{"id":1507,"date":"2021-08-24T11:00:00","date_gmt":"2021-08-23T23:00:00","guid":{"rendered":"https:\/\/ostermanresearch.com\/?p=1507"},"modified":"2025-03-11T06:52:08","modified_gmt":"2025-03-10T17:52:08","slug":"critically-vulnerable-open-source-code-found-in-cots-apps-interview","status":"publish","type":"post","link":"https:\/\/ostermanresearch.com\/2021\/08\/24\/critically-vulnerable-open-source-code-found-in-cots-apps-interview\/","title":{"rendered":"Critically Vulnerable Open Source Code Found in COTS Apps &#8211; interview with Shift Left Academy"},"content":{"rendered":"\n<p><em>Interview with <strong>Deb Radcliff<\/strong>, <strong>Shift Left Academy<\/strong>, <strong>GrammaTech<\/strong><\/em><\/p>\n\n\n\n<p><em>Date: <strong>August 24, 2021<\/strong><\/em><\/p>\n\n\n\n<p>On August 4, Osterman Research released a software supply chain study conducted against data collected by GrammaTech\u2019s CodeSentry Software Supply Chain testing product. The study of that data found that 100 percent of commercial applications that use open-source components contain vulnerabilities within their open-source components, and that 85% of the browser, email, file sharing, online meeting and messaging products tested had at least one critical vulnerability with a 10.0 CVSS (Common Vulnerability Scoring System) score, which is the highest possible.&nbsp;<\/p>\n\n\n\n<p>In this video interview,&nbsp;Michael Sampson,&nbsp;Senior Analyst Osterman Research and author of the report discusses his findings and offers advice on how to avoid some of the pitfalls of open source.&nbsp;<\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link\" href=\"https:\/\/shiftleft.grammatech.com\/critically-vulnerable-open-source-code-found-in-cots-apps-michael-sampson-osterman\" target=\"_blank\" rel=\"noreferrer noopener\">Watch the interview<\/a><\/div>\n<\/div>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Discussing the findings on vulnerable open-source components in commercial off-the-shelf software. A conversation between Deb Radcliff for GrammaTech&#8217;s Shift Left Academy and Michael Sampson from Osterman Research.<\/p>\n","protected":false},"author":384585,"featured_media":4484,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[712027168,49786],"tags":[712027183],"class_list":["post-1507","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-security-threats","tag-interview"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2021\/08\/grammatech2021.jpg?fit=1160%2C350&ssl=1","jetpack_likes_enabled":false,"jetpack_sharing_enabled":false,"jetpack_shortlink":"https:\/\/wp.me\/pcHAk4-oj","_links":{"self":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/1507","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/users\/384585"}],"replies":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/comments?post=1507"}],"version-history":[{"count":9,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/1507\/revisions"}],"predecessor-version":[{"id":3303,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/1507\/revisions\/3303"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media\/4484"}],"wp:attachment":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media?parent=1507"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/categories?post=1507"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/tags?post=1507"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}