Skip to content

Commit 7b593d0

Browse files
committed
chore: update security scan results
- Updated scan data from workflow run 126 - Scan mode: git-only - Total scanned: 160 - Total vulnerabilities: 478
1 parent 6263dfb commit 7b593d0

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

43 files changed

+325
-115
lines changed

data/master-d1b91b79b5.json

Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"release_version": "master-d1b91b79b5",
3+
"scan_date": "2025-11-06T00:28:37.895988Z",
4+
"tool_version": "0.21.0",
5+
"total_components": 0,
6+
"vulnerabilities": [
7+
{
8+
"cve_id": "CVE-2025-54764",
9+
"component": "mbed_tls",
10+
"component_version": "3.6.4",
11+
"severity": "MEDIUM",
12+
"score": "6.2",
13+
"vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
14+
"description": "Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.",
15+
"link": "https://nvd.nist.gov/vuln/detail/CVE-2025-54764"
16+
},
17+
{
18+
"cve_id": "CVE-2025-59438",
19+
"component": "mbed_tls",
20+
"component_version": "3.6.4",
21+
"severity": "MEDIUM",
22+
"score": "5.3",
23+
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
24+
"description": "Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.",
25+
"link": "https://nvd.nist.gov/vuln/detail/CVE-2025-59438"
26+
}
27+
],
28+
"summary": {
29+
"total_vulnerabilities": 2,
30+
"by_severity": {
31+
"CRITICAL": 0,
32+
"HIGH": 0,
33+
"MEDIUM": 2,
34+
"LOW": 0
35+
}
36+
},
37+
"metadata": {
38+
"scanner": "esp-idf-security-dashboard",
39+
"scan_method": "git-release-branch",
40+
"docker_image": null
41+
}
42+
}

data/release_v5.0-d9f9b7d8ed.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"release_version": "release/v5.0-d9f9b7d8ed",
3-
"scan_date": "2025-11-05T00:27:48.349482Z",
3+
"scan_date": "2025-11-06T00:27:48.401919Z",
44
"tool_version": "0.21.0",
55
"total_components": 0,
66
"vulnerabilities": [

data/release_v5.1-79c0dff3a5.json

Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"release_version": "release/v5.1-79c0dff3a5",
3+
"scan_date": "2025-11-06T00:27:56.238875Z",
4+
"tool_version": "0.21.0",
5+
"total_components": 0,
6+
"vulnerabilities": [
7+
{
8+
"cve_id": "CVE-2025-54764",
9+
"component": "mbed_tls",
10+
"component_version": "3.6.4",
11+
"severity": "MEDIUM",
12+
"score": "6.2",
13+
"vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
14+
"description": "Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.",
15+
"link": "https://nvd.nist.gov/vuln/detail/CVE-2025-54764"
16+
},
17+
{
18+
"cve_id": "CVE-2025-59438",
19+
"component": "mbed_tls",
20+
"component_version": "3.6.4",
21+
"severity": "MEDIUM",
22+
"score": "5.3",
23+
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
24+
"description": "Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.",
25+
"link": "https://nvd.nist.gov/vuln/detail/CVE-2025-59438"
26+
}
27+
],
28+
"summary": {
29+
"total_vulnerabilities": 2,
30+
"by_severity": {
31+
"CRITICAL": 0,
32+
"HIGH": 0,
33+
"MEDIUM": 2,
34+
"LOW": 0
35+
}
36+
},
37+
"metadata": {
38+
"scanner": "esp-idf-security-dashboard",
39+
"scan_method": "git-release-branch",
40+
"docker_image": null
41+
}
42+
}

data/release_v5.2-72d06017df.json

Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"release_version": "release/v5.2-72d06017df",
3+
"scan_date": "2025-11-06T00:28:12.508565Z",
4+
"tool_version": "0.21.0",
5+
"total_components": 0,
6+
"vulnerabilities": [
7+
{
8+
"cve_id": "CVE-2025-54764",
9+
"component": "mbed_tls",
10+
"component_version": "3.6.4",
11+
"severity": "MEDIUM",
12+
"score": "6.2",
13+
"vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
14+
"description": "Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.",
15+
"link": "https://nvd.nist.gov/vuln/detail/CVE-2025-54764"
16+
},
17+
{
18+
"cve_id": "CVE-2025-59438",
19+
"component": "mbed_tls",
20+
"component_version": "3.6.4",
21+
"severity": "MEDIUM",
22+
"score": "5.3",
23+
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
24+
"description": "Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.",
25+
"link": "https://nvd.nist.gov/vuln/detail/CVE-2025-59438"
26+
}
27+
],
28+
"summary": {
29+
"total_vulnerabilities": 2,
30+
"by_severity": {
31+
"CRITICAL": 0,
32+
"HIGH": 0,
33+
"MEDIUM": 2,
34+
"LOW": 0
35+
}
36+
},
37+
"metadata": {
38+
"scanner": "esp-idf-security-dashboard",
39+
"scan_method": "git-release-branch",
40+
"docker_image": null
41+
}
42+
}

data/release_v5.3-e807677650.json

Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"release_version": "release/v5.3-e807677650",
3+
"scan_date": "2025-11-06T00:28:29.573802Z",
4+
"tool_version": "0.21.0",
5+
"total_components": 0,
6+
"vulnerabilities": [
7+
{
8+
"cve_id": "CVE-2025-54764",
9+
"component": "mbed_tls",
10+
"component_version": "3.6.4",
11+
"severity": "MEDIUM",
12+
"score": "6.2",
13+
"vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
14+
"description": "Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.",
15+
"link": "https://nvd.nist.gov/vuln/detail/CVE-2025-54764"
16+
},
17+
{
18+
"cve_id": "CVE-2025-59438",
19+
"component": "mbed_tls",
20+
"component_version": "3.6.4",
21+
"severity": "MEDIUM",
22+
"score": "5.3",
23+
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
24+
"description": "Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.",
25+
"link": "https://nvd.nist.gov/vuln/detail/CVE-2025-59438"
26+
}
27+
],
28+
"summary": {
29+
"total_vulnerabilities": 2,
30+
"by_severity": {
31+
"CRITICAL": 0,
32+
"HIGH": 0,
33+
"MEDIUM": 2,
34+
"LOW": 0
35+
}
36+
},
37+
"metadata": {
38+
"scanner": "esp-idf-security-dashboard",
39+
"scan_method": "git-release-branch",
40+
"docker_image": null
41+
}
42+
}

data/release_v5.4-616ff5862b.json

Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"release_version": "release/v5.4-616ff5862b",
3+
"scan_date": "2025-11-06T00:28:04.795900Z",
4+
"tool_version": "0.21.0",
5+
"total_components": 0,
6+
"vulnerabilities": [
7+
{
8+
"cve_id": "CVE-2025-54764",
9+
"component": "mbed_tls",
10+
"component_version": "3.6.4",
11+
"severity": "MEDIUM",
12+
"score": "6.2",
13+
"vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
14+
"description": "Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.",
15+
"link": "https://nvd.nist.gov/vuln/detail/CVE-2025-54764"
16+
},
17+
{
18+
"cve_id": "CVE-2025-59438",
19+
"component": "mbed_tls",
20+
"component_version": "3.6.4",
21+
"severity": "MEDIUM",
22+
"score": "5.3",
23+
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
24+
"description": "Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.",
25+
"link": "https://nvd.nist.gov/vuln/detail/CVE-2025-59438"
26+
}
27+
],
28+
"summary": {
29+
"total_vulnerabilities": 2,
30+
"by_severity": {
31+
"CRITICAL": 0,
32+
"HIGH": 0,
33+
"MEDIUM": 2,
34+
"LOW": 0
35+
}
36+
},
37+
"metadata": {
38+
"scanner": "esp-idf-security-dashboard",
39+
"scan_method": "git-release-branch",
40+
"docker_image": null
41+
}
42+
}

data/release_v5.5-f1a1df9b2e.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"release_version": "release/v5.5-f1a1df9b2e",
3-
"scan_date": "2025-11-05T00:27:39.918002Z",
3+
"scan_date": "2025-11-06T00:28:20.928514Z",
44
"tool_version": "0.21.0",
55
"total_components": 0,
66
"vulnerabilities": [

data/scan_summary.json

Lines changed: 38 additions & 38 deletions
Original file line numberDiff line numberDiff line change
@@ -1,61 +1,61 @@
11
{
2-
"last_updated": "2025-11-05T00:28:05.594992Z",
2+
"last_updated": "2025-11-06T00:28:37.896430Z",
33
"scanned_versions": [
4-
"v5.4.1",
5-
"v5.3.2",
6-
"v5.0.3",
7-
"v5.0.9",
8-
"v5.3",
9-
"v5.1.1",
10-
"v5.0.1",
11-
"v5.0.5",
124
"v5.1.5",
5+
"v5.0.1",
136
"v5.1.3",
7+
"v5.0",
8+
"v5.1.4",
9+
"v5.4",
10+
"v5.2.3",
11+
"v5.4.1",
12+
"v5.0.9",
13+
"v5.1.6",
14+
"v5.0.8",
1415
"v5.3.3",
15-
"v5.2.6",
16+
"v5.2.1",
1617
"v5.5.1",
17-
"v5.3.1",
18+
"v5.0.7",
19+
"v5.3",
1820
"v5.1",
1921
"v5.2.4",
20-
"v5.3.4",
21-
"v5.4",
22-
"v5.4.3",
23-
"v5.1.4",
24-
"v5.0.6",
25-
"v5.2.3",
26-
"v5.2.5",
27-
"v5.0.7",
28-
"v5.2.1",
29-
"v5.1.2",
30-
"v5.0.4",
22+
"v5.2.6",
3123
"v5.0.2",
32-
"v5.0.8",
33-
"v5.2.2",
34-
"v5.0",
35-
"v5.1.6",
24+
"v5.2",
25+
"v5.1.1",
26+
"v5.0.4",
3627
"v5.4.2",
28+
"v5.4.3",
3729
"v5.5",
38-
"v5.2",
39-
"release/v5.2-083e2bb56a",
40-
"release/v5.3-13ec3f6f6f",
41-
"release/v5.4-c94fdcdb48",
42-
"release/v5.5-f1a1df9b2e",
30+
"v5.3.2",
31+
"v5.0.5",
32+
"v5.3.4",
33+
"v5.2.2",
34+
"v5.0.3",
35+
"v5.2.5",
36+
"v5.3.1",
37+
"v5.1.2",
38+
"v5.0.6",
4339
"release/v5.0-d9f9b7d8ed",
44-
"release/v5.1-dd37234fff",
45-
"master-ff97953b32"
40+
"release/v5.1-79c0dff3a5",
41+
"release/v5.4-616ff5862b",
42+
"release/v5.2-72d06017df",
43+
"release/v5.5-f1a1df9b2e",
44+
"release/v5.3-e807677650",
45+
"master-d1b91b79b5"
4646
],
4747
"failed_versions": [
48-
"release/v5.2",
49-
"release/v5.3",
50-
"release/v5.4",
51-
"release/v5.5",
5248
"release/v5.0",
5349
"release/v5.1",
50+
"release/v5.4",
51+
"release/v5.2",
52+
"release/v5.5",
53+
"release/v5.3",
5454
"master"
5555
],
5656
"total_scanned": 42,
5757
"scan_method": "git-batch",
58-
"workflow_run": "125",
58+
"workflow_run": "126",
5959
"scanner_info": {
6060
"tool": "esp-idf-security-dashboard",
6161
"esp_idf_sbom_version": "0.21.0",

data/v5.0.1.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"release_version": "v5.0.1",
3-
"scan_date": "2025-11-05T00:23:34.743758Z",
3+
"scan_date": "2025-11-06T00:23:30.293204Z",
44
"tool_version": "0.21.0",
55
"total_components": 0,
66
"vulnerabilities": [],

data/v5.0.2.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"release_version": "v5.0.2",
3-
"scan_date": "2025-11-05T00:26:14.099881Z",
3+
"scan_date": "2025-11-06T00:25:43.475679Z",
44
"tool_version": "0.21.0",
55
"total_components": 0,
66
"vulnerabilities": [],

0 commit comments

Comments
 (0)