{"id":4479,"date":"2021-08-10T12:00:00","date_gmt":"2021-08-10T00:00:00","guid":{"rendered":"https:\/\/ostermanresearch.com\/?post_type=jetpack-portfolio&#038;p=4479"},"modified":"2025-03-10T07:46:58","modified_gmt":"2025-03-09T18:46:58","slug":"grammatech-open-source-vulnerable","status":"publish","type":"jetpack-portfolio","link":"https:\/\/ostermanresearch.com\/portfolio\/grammatech-open-source-vulnerable\/","title":{"rendered":"Uncovering the Presence of Vulnerable Open-Source Components in Commercial Software &#8211; commissioned by GrammaTech"},"content":{"rendered":"\n<p><em>Commissioned by<strong> GrammaTech<\/strong><\/em><\/p>\n\n\n\n<p><em>Published <strong>August 2021<\/strong><\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Executive summary<\/h2>\n\n\n\n<p>Commercial off-the-shelf software often includes open-source software components, but vendors frequently do not disclose details of the presence of such components. Many open-source components contain a range of known vulnerabilities that can be used as egress points for cyberattack. This lack of awareness of open-source components used by organizations in commercial off-the-shelf software increases the security risk, attack surface, and potential for compromise by cybercriminals.<\/p>\n\n\n\n<p>In this white paper, we present the findings of an investigation into the use of open-source components in commercial off-the-shelf software\u2014many of which have a list of known vulnerabilities\u2014across five common software categories. The base data was generated by GrammaTech using its CodeSentry software supply chain security product. CodeSentry uses multiple methods of identifying open-source components used in commercial off-the-shelf software that is delivered in binary form. CodeSentry does not need access to the vendor\u2019s source code to complete its analysis of included open-source components.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link has-white-color has-vivid-purple-background-color has-text-color has-background has-link-color wp-element-button\" href=\"https:\/\/f.hubspotusercontent20.net\/hubfs\/582328\/Osterman%20Research%20White%20Paper%20-%20Vulnerable%20Open-Source%20Components%20-%20GrammaTech%20-%20August%202021.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Download from GrammaTech<\/a><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The findings of an investigation into the use of open-source components in commercial off-the-shelf software\u2014many of which have a list of known vulnerabilities\u2014across five common software categories. Commissioned by GrammaTech.<\/p>\n","protected":false},"author":384585,"featured_media":4484,"comment_status":"closed","ping_status":"closed","template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_post_was_ever_published":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"jetpack-portfolio-type":[712027439],"jetpack-portfolio-tag":[712027455,712027441,712027480],"class_list":["post-4479","jetpack-portfolio","type-jetpack-portfolio","status-publish","format-standard","has-post-thumbnail","hentry","jetpack-portfolio-type-commissioned-research","jetpack-portfolio-tag-application-security","jetpack-portfolio-tag-cybersecurity","jetpack-portfolio-tag-software-supply-chain"],"jetpack_publicize_connections":[],"jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/jetpack-portfolio\/4479","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/jetpack-portfolio"}],"about":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/types\/jetpack-portfolio"}],"author":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/users\/384585"}],"replies":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/comments?post=4479"}],"version-history":[{"count":4,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/jetpack-portfolio\/4479\/revisions"}],"predecessor-version":[{"id":4483,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/jetpack-portfolio\/4479\/revisions\/4483"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media\/4484"}],"wp:attachment":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media?parent=4479"}],"wp:term":[{"taxonomy":"jetpack-portfolio-type","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/jetpack-portfolio-type?post=4479"},{"taxonomy":"jetpack-portfolio-tag","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/jetpack-portfolio-tag?post=4479"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}