SlideShare a Scribd company logo
Open Source Insight:
Equifax, Apache Struts, & CVE-2017-5638 Vulnerability
By Fred Bals | Senior Content Writer/Editor
Cybersecurity News This Week
It’s an all Equifax breach/Apache Struts/ CVE-2017-5638 issue of Open
Source Insight this week as we examine how an unpatched open source
flaw and an apparent lack of diligence exposed sensitive data for over
140 million US consumers. We look at what happened, how you can see
if you’ve been affected by the breach, and discuss whether you should
replace Struts with another framework.
Also recommended reading are the following articles from the Black Duck
blog, which you should subscribe to for the latest open source security
news. Black Duck was blogging on CVE-2017-5638 and what you could
do to protect yourself against the vulnerability from its initial disclosure in
March.
• Equifax Hackers Stole 200k Credit Card
Accounts in One Fell Swoop
• Why the Equifax Breach Should Never Have
Happened
• Did Lack of Visibility into Apache Struts Lead
to the Equifax Breach?
• Unpatched Open Source Software Flaw
Blamed for Massive Equifax Breach
Open Source News
More Open Source News
• Should You Replace Apache Struts?
Maybe. Or, Maybe Not.
• Failure to Patch Two-month-old Bug Led
to Massive Equifax Breach
• See if You Were Affected by the Equifax
Cybersecurity Incident
• (Webinar) Behind the Equifax Breach: A
Deep Dive Into Apache Struts CVE-2017-
5638
via the Black Duck Blog:
• Critical Vulnerability CVE-2017-5638 Attacks
Escalating
• CVE-2017-5638: Anatomy of the Apache Struts
Vulnerability
• Pandora’s Box – Exploits Show Package
Manager Blind Spots
• "Easy" to Hack Apache Struts Vulnerability
CVE-2017-9805
Apache Struts Vulnerability Information
Equifax Hackers Stole 200k Credit Card
Accounts in One Fell Swoop
via Krebs on Security: Visa and MasterCard are sending
confidential alerts to financial institutions across the United
States this week, warning them about more than 200,000
credit cards that were stolen in the epic data breach
announced last week at big-three credit bureau Equifax. At first
glance, the private notices obtained by KrebsOnSecurity
appear to suggest that hackers initially breached Equifax
starting in November 2016. But Equifax says the accounts
were all stolen at the same time — when hackers accessed
the company’s systems in mid-May 2017.
via TechBeacon: Mike Pittenger, VP of security
strategy at Black Duck Software, looks at the
causes of the Equifax breach and what your
team can do to prevent something similar
happening to your organization.
Why the Equifax Breach Should Never
Have Happened
Did Lack of Visibility into Apache Struts
Lead to the Equifax Breach?
via Black Duck blog (Patrick Carey): The Apache Struts Project
Management Committee released a statement regarding the Equifax
breach that includes excellent suggestions for securing any open or
closed source supporting libraries in software products and services,
which I'll share verbatim.
via eSecurity Planet: It's no surprise that Web
application attacks are the leading cause of
large breaches. The *average* Web application
or API has 26.7 serious vulnerabilities. And
organizations often have hundreds, thousands,
or even tens of thousands of applications.
Unpatched Open Source Software Flaw
Blamed for Massive Equifax Breach
Should You Replace Apache Struts?
Maybe. Or, Maybe Not.
via Black Duck blog (Tim Mackey): The easy answer to the
question is “it depends.” It’s been one hell of a year for Apache
Struts. With the latest round of security disclosures comingled with
the Equifax data breach, it's reasonable for users of Struts to start
questioning if they should be migrating to another framework. After
all, there have been five possible remote code execution
disclosures this year, and that’s quite a lot.
via Ars Technica: As Ars warned in March, patching the
security hole was labor intensive and difficult, in part
because it involved downloading an updated version of
Struts and then using it to rebuild all apps that used
older, buggy Struts versions. Some websites may
depend on dozens or even hundreds of such apps,
which may be scattered across dozens of servers on
multiple continents. Once rebuilt, the apps must be
extensively tested before going into production to ensure
they don't break key functions on the site.
Failure to Patch Two-month-old Bug Led to Massive
Equifax Breach
See if You Were Affected by the Equifax
Cybersecurity Incident
via Equifax: To determine if your personal information may have
been impacted and for steps to protect your information, please
visit https://www.equifaxsecurity2017.com/. We recommend that
consumers be vigilant in reviewing their account statements and
credit reports, and that they immediately report any unauthorized
activity to their financial institutions. We also recommend that they
monitor their personal information and visit the Federal Trade
Commission’s website, www.ftc.gov/idtheft, to obtain information
about steps they can take to better protect against identity theft as
well as information about fraud alerts and security freezes.
via New York Times: On Tuesday, the
company said it would waive all fees until Nov.
21 for people who want to freeze their Equifax
credit files. It will also refund any fees that
anyone has paid since Thursday, though the
company would not say whether this would be
automatic.
Equifax, Bowing to Public Pressure,
Drops Credit-Freeze Fees
(Webinar) Behind the Equifax Breach: A Deep
Dive Into Apache Struts CVE-2017-5638
Equifax confirmed that their high profile, high impact data breach was
due to an exploit of a vulnerability in an open source component,
Apache Struts CVE-2017-5638. Apache Struts is a mainstream web
framework, widely used by Fortune 100 companies in education,
government, financial services, retail and media. Black Duck open
source security experts share their analysis of what happened at
Equifax and provide you with guidance to help your company avoid
being the next front page news story. Join the webinar October 5 at
11 AM EST.
(Watch on demand after 10/5/17)
Subscribe
Stay up to date on open source security and cybersecurity –
subscribe to our blog today.
Open Source Insight:  Equifax, Apache Struts, & CVE-2017-5638 Vulnerability

More Related Content

PPTX
Open Source Insight: CVE–2017-9805, Equifax Breach & Wacky Open Source Licenses
PPTX
Threat Check for Struts Released, Equifax Breach Dominates News
PPTX
Equifax breach - how to lose friends and customers...
DOCX
Why security is the kidney not the tail of the dog v3
PDF
The growing hacking threat to websites
PPTX
Are Your IT Systems Secure?
PPTX
Equifax Breach - Lessons - Cyber Rescue - 16th may 2018
Open Source Insight: CVE–2017-9805, Equifax Breach & Wacky Open Source Licenses
Threat Check for Struts Released, Equifax Breach Dominates News
Equifax breach - how to lose friends and customers...
Why security is the kidney not the tail of the dog v3
The growing hacking threat to websites
Are Your IT Systems Secure?
Equifax Breach - Lessons - Cyber Rescue - 16th may 2018

What's hot (19)

PDF
Security Firm Program - Corporate College
PPTX
BSidesTO 2016 - Incident Tracking
PDF
The Internet Is a Dog-Eat-Dog World, and Your App Is Clad in Milk-Bone Underwear
PPTX
Solnet dev secops meetup
PDF
Thecavalryisus owasp eee-oct2015_v2
PPTX
2015 Microsoft Vulnerabilities Report
PDF
Deepfake anyone, the ai synthetic media industry enters a dangerous phase
PDF
The Internet is a dog-eat-dog world and your app is clad in Milk Bone underwear
PPTX
Webinar notes: Welcome to your worst day ever
PDF
Patches Arrren't Just for Pirates
PDF
Briskinfosec - Threatsploit Report Augest 2021- Cyber security updates
PPTX
How to Rapidly Identify Assets at Risk to WannaCry Ransomware
PDF
COVID-19 free penetration tests by Pentest-Tools.com
PDF
CSS Trivia
PDF
5 must-have security testing tools for your pentesting tasks
PDF
CSS 2018 Trivia
PDF
Don’t let Your Website Spread Malware – a New Approach to Web App Security
PDF
Websense 2013 Threat Report
PPTX
2017 Security Report Presentation
Security Firm Program - Corporate College
BSidesTO 2016 - Incident Tracking
The Internet Is a Dog-Eat-Dog World, and Your App Is Clad in Milk-Bone Underwear
Solnet dev secops meetup
Thecavalryisus owasp eee-oct2015_v2
2015 Microsoft Vulnerabilities Report
Deepfake anyone, the ai synthetic media industry enters a dangerous phase
The Internet is a dog-eat-dog world and your app is clad in Milk Bone underwear
Webinar notes: Welcome to your worst day ever
Patches Arrren't Just for Pirates
Briskinfosec - Threatsploit Report Augest 2021- Cyber security updates
How to Rapidly Identify Assets at Risk to WannaCry Ransomware
COVID-19 free penetration tests by Pentest-Tools.com
CSS Trivia
5 must-have security testing tools for your pentesting tasks
CSS 2018 Trivia
Don’t let Your Website Spread Malware – a New Approach to Web App Security
Websense 2013 Threat Report
2017 Security Report Presentation
Ad

Similar to Open Source Insight: Equifax, Apache Struts, & CVE-2017-5638 Vulnerability (20)

PDF
Equifax & Apache Struts Vulnerability CVE-2017-5638
PPTX
[OWASP Poland Day] Application frameworks' vulnerabilities
PDF
The Intersection Between Open Source and Cybersecurity
PDF
Equifax Data Breach: A Costly Cyber Failure
PPTX
Open Source Insight: GDPR Best Practices, Struts RCE Vulns, SAST, DAST & Equ...
PPTX
Open Source Insight: Amazon Servers Exposed Open Source & the Public Sector...
PDF
RSAC DevSecOpsDays 2018 - We are all Equifax
PPTX
Java application security the hard way - a workshop for the serious developer
PPTX
State of the Software Supply Chain Report 2017
DOCX
The Equifax Data Breach Case Page 1 of 4 Equifax, alo.docx
DOCX
The Equifax Data Breach Case Page 1 of 4 Equifax, alo.docx
PDF
In May 2017, it was revealed that Equifax has joined other high-prof.pdf
PPT
Equifax
PDF
Cyber Threats
PPTX
Equifax Breach Postmortem
PPTX
Equifax data breach
PPSX
Manoj Purandare - Application Security - Secure Code Assessment Program - Pre...
PPTX
Manoj Purandare - Application Security - Secure Code Assessment Program - Pre...
PPTX
Manoj Purandare - Application Security - Secure Code Assessment Program - Pre...
PPTX
Securing Modern Applications: The Data Behind DevSecOps
Equifax & Apache Struts Vulnerability CVE-2017-5638
[OWASP Poland Day] Application frameworks' vulnerabilities
The Intersection Between Open Source and Cybersecurity
Equifax Data Breach: A Costly Cyber Failure
Open Source Insight: GDPR Best Practices, Struts RCE Vulns, SAST, DAST & Equ...
Open Source Insight: Amazon Servers Exposed Open Source & the Public Sector...
RSAC DevSecOpsDays 2018 - We are all Equifax
Java application security the hard way - a workshop for the serious developer
State of the Software Supply Chain Report 2017
The Equifax Data Breach Case Page 1 of 4 Equifax, alo.docx
The Equifax Data Breach Case Page 1 of 4 Equifax, alo.docx
In May 2017, it was revealed that Equifax has joined other high-prof.pdf
Equifax
Cyber Threats
Equifax Breach Postmortem
Equifax data breach
Manoj Purandare - Application Security - Secure Code Assessment Program - Pre...
Manoj Purandare - Application Security - Secure Code Assessment Program - Pre...
Manoj Purandare - Application Security - Secure Code Assessment Program - Pre...
Securing Modern Applications: The Data Behind DevSecOps
Ad

More from Black Duck by Synopsys (20)

PDF
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
PDF
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
PDF
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
PDF
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
PDF
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
PDF
Open-Source- Sicherheits- und Risikoanalyse 2018
PDF
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
PDF
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
PDF
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
PDF
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
PPT
FLIGHT Amsterdam Presentation - From Protex to Hub
PPTX
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
PPTX
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
PDF
Open Source Rookies and Community
PPTX
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
PPTX
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
PPTX
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
PPTX
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
PPTX
Open Source Insight: Happy Birthday Open Source and Application Security for ...
PPTX
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
Open-Source- Sicherheits- und Risikoanalyse 2018
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
FLIGHT Amsterdam Presentation - From Protex to Hub
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Open Source Rookies and Community
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
Open Source Insight: Happy Birthday Open Source and Application Security for ...
Open Source Insight: Security Breaches and Cryptocurrency Dominating News

Recently uploaded (20)

PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPTX
sap open course for s4hana steps from ECC to s4
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
Machine Learning_overview_presentation.pptx
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
A comparative analysis of optical character recognition models for extracting...
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Electronic commerce courselecture one. Pdf
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Empathic Computing: Creating Shared Understanding
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Building Integrated photovoltaic BIPV_UPV.pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
sap open course for s4hana steps from ECC to s4
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
“AI and Expert System Decision Support & Business Intelligence Systems”
Machine Learning_overview_presentation.pptx
MIND Revenue Release Quarter 2 2025 Press Release
gpt5_lecture_notes_comprehensive_20250812015547.pdf
A comparative analysis of optical character recognition models for extracting...
Programs and apps: productivity, graphics, security and other tools
Reach Out and Touch Someone: Haptics and Empathic Computing
Electronic commerce courselecture one. Pdf
The Rise and Fall of 3GPP – Time for a Sabbatical?
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Empathic Computing: Creating Shared Understanding
Dropbox Q2 2025 Financial Results & Investor Presentation
Digital-Transformation-Roadmap-for-Companies.pptx
Network Security Unit 5.pdf for BCA BBA.
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows

Open Source Insight: Equifax, Apache Struts, & CVE-2017-5638 Vulnerability

  • 1. Open Source Insight: Equifax, Apache Struts, & CVE-2017-5638 Vulnerability By Fred Bals | Senior Content Writer/Editor
  • 2. Cybersecurity News This Week It’s an all Equifax breach/Apache Struts/ CVE-2017-5638 issue of Open Source Insight this week as we examine how an unpatched open source flaw and an apparent lack of diligence exposed sensitive data for over 140 million US consumers. We look at what happened, how you can see if you’ve been affected by the breach, and discuss whether you should replace Struts with another framework. Also recommended reading are the following articles from the Black Duck blog, which you should subscribe to for the latest open source security news. Black Duck was blogging on CVE-2017-5638 and what you could do to protect yourself against the vulnerability from its initial disclosure in March.
  • 3. • Equifax Hackers Stole 200k Credit Card Accounts in One Fell Swoop • Why the Equifax Breach Should Never Have Happened • Did Lack of Visibility into Apache Struts Lead to the Equifax Breach? • Unpatched Open Source Software Flaw Blamed for Massive Equifax Breach Open Source News
  • 4. More Open Source News • Should You Replace Apache Struts? Maybe. Or, Maybe Not. • Failure to Patch Two-month-old Bug Led to Massive Equifax Breach • See if You Were Affected by the Equifax Cybersecurity Incident • (Webinar) Behind the Equifax Breach: A Deep Dive Into Apache Struts CVE-2017- 5638
  • 5. via the Black Duck Blog: • Critical Vulnerability CVE-2017-5638 Attacks Escalating • CVE-2017-5638: Anatomy of the Apache Struts Vulnerability • Pandora’s Box – Exploits Show Package Manager Blind Spots • "Easy" to Hack Apache Struts Vulnerability CVE-2017-9805 Apache Struts Vulnerability Information
  • 6. Equifax Hackers Stole 200k Credit Card Accounts in One Fell Swoop via Krebs on Security: Visa and MasterCard are sending confidential alerts to financial institutions across the United States this week, warning them about more than 200,000 credit cards that were stolen in the epic data breach announced last week at big-three credit bureau Equifax. At first glance, the private notices obtained by KrebsOnSecurity appear to suggest that hackers initially breached Equifax starting in November 2016. But Equifax says the accounts were all stolen at the same time — when hackers accessed the company’s systems in mid-May 2017.
  • 7. via TechBeacon: Mike Pittenger, VP of security strategy at Black Duck Software, looks at the causes of the Equifax breach and what your team can do to prevent something similar happening to your organization. Why the Equifax Breach Should Never Have Happened
  • 8. Did Lack of Visibility into Apache Struts Lead to the Equifax Breach? via Black Duck blog (Patrick Carey): The Apache Struts Project Management Committee released a statement regarding the Equifax breach that includes excellent suggestions for securing any open or closed source supporting libraries in software products and services, which I'll share verbatim.
  • 9. via eSecurity Planet: It's no surprise that Web application attacks are the leading cause of large breaches. The *average* Web application or API has 26.7 serious vulnerabilities. And organizations often have hundreds, thousands, or even tens of thousands of applications. Unpatched Open Source Software Flaw Blamed for Massive Equifax Breach
  • 10. Should You Replace Apache Struts? Maybe. Or, Maybe Not. via Black Duck blog (Tim Mackey): The easy answer to the question is “it depends.” It’s been one hell of a year for Apache Struts. With the latest round of security disclosures comingled with the Equifax data breach, it's reasonable for users of Struts to start questioning if they should be migrating to another framework. After all, there have been five possible remote code execution disclosures this year, and that’s quite a lot.
  • 11. via Ars Technica: As Ars warned in March, patching the security hole was labor intensive and difficult, in part because it involved downloading an updated version of Struts and then using it to rebuild all apps that used older, buggy Struts versions. Some websites may depend on dozens or even hundreds of such apps, which may be scattered across dozens of servers on multiple continents. Once rebuilt, the apps must be extensively tested before going into production to ensure they don't break key functions on the site. Failure to Patch Two-month-old Bug Led to Massive Equifax Breach
  • 12. See if You Were Affected by the Equifax Cybersecurity Incident via Equifax: To determine if your personal information may have been impacted and for steps to protect your information, please visit https://www.equifaxsecurity2017.com/. We recommend that consumers be vigilant in reviewing their account statements and credit reports, and that they immediately report any unauthorized activity to their financial institutions. We also recommend that they monitor their personal information and visit the Federal Trade Commission’s website, www.ftc.gov/idtheft, to obtain information about steps they can take to better protect against identity theft as well as information about fraud alerts and security freezes.
  • 13. via New York Times: On Tuesday, the company said it would waive all fees until Nov. 21 for people who want to freeze their Equifax credit files. It will also refund any fees that anyone has paid since Thursday, though the company would not say whether this would be automatic. Equifax, Bowing to Public Pressure, Drops Credit-Freeze Fees
  • 14. (Webinar) Behind the Equifax Breach: A Deep Dive Into Apache Struts CVE-2017-5638 Equifax confirmed that their high profile, high impact data breach was due to an exploit of a vulnerability in an open source component, Apache Struts CVE-2017-5638. Apache Struts is a mainstream web framework, widely used by Fortune 100 companies in education, government, financial services, retail and media. Black Duck open source security experts share their analysis of what happened at Equifax and provide you with guidance to help your company avoid being the next front page news story. Join the webinar October 5 at 11 AM EST. (Watch on demand after 10/5/17)
  • 15. Subscribe Stay up to date on open source security and cybersecurity – subscribe to our blog today.