diff --git a/SECURITY.md b/SECURITY.md index 1533fdece1..df09a0eea0 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -35,25 +35,42 @@ See : https://github.com/eclipse/californium/security/policy - 2.0.0-M7 + + 2.0.0-M8 + :heavy_check_mark: - 2.0.0-M5 -> 2.0.0-M6 + 2.0.0-M6 -> 2.0.0-M7 :x: - GHSA-fj2w-wfgv-mwq6 - dependency (com.upokecenter.cbor) - CBOR or SenML-CBOR decoding + CVE-2022-2576 + dependency (californium/scandium) + DTLS_VERIFY_PEERS_ ON_RESUMPTION_THRESHOLD > 0 - 2.0.0-M2 -> 2.0.0-M4 + 2.0.0-M5 -> 2.0.0-M6 :x: + CVE-2022-2576 + dependency (californium/scandium) + DTLS_VERIFY_PEERS_ ON_RESUMPTION_THRESHOLD > 0 + + GHSA-fj2w-wfgv-mwq6 + dependency (com.upokecenter.cbor) + CBOR or SenML-CBOR decoding + + + + 2.0.0-M2 -> 2.0.0-M4 + :x: + CVE-2022-2576 + dependency (californium/scandium) + DTLS_VERIFY_PEERS_ ON_RESUMPTION_THRESHOLD > 0 + CVE-2021-34433 dependency (californium/scandium) DTLS with x509 and/or RPK + GHSA-fj2w-wfgv-mwq6 dependency (com.upokecenter.cbor) @@ -61,34 +78,56 @@ See : https://github.com/eclipse/californium/security/policy - 2.0.0-M1 - :x: - CVE-2021-34433 - dependency (californium/scandium) - DTLS with x509 and/or RPK + 2.0.0-M1 + :x: + CVE-2022-2576 + dependency (californium/scandium) + DTLS_VERIFY_PEERS_ ON_RESUMPTION_THRESHOLD > 0 + + CVE-2021-34433 + dependency (californium/scandium) + DTLS with x509 and/or RPK + - - 1.3.2 + + + 1.4.1 :heavy_check_mark: - 1.1.0 -> 1.3.1 + 1.3.1 -> 1.4.0 :x: - CVE-2020-27222 - CVE-2021-34433 - + CVE-2022-2576 dependency (californium/scandium) - DTLS with x509 and/or RPK + DTLS_VERIFY_PEERS_ ON_RESUMPTION_THRESHOLD > 0 - 1.0.0 -> 1.0.2 - :x: - CVE-2021-34433 - dependency (californium/scandium) - DTLS with x509 and/or RPK + 1.1.0 -> 1.3.1 + :x: + CVE-2022-2576 + dependency (californium/scandium) + DTLS_VERIFY_PEERS_ ON_RESUMPTION_THRESHOLD > 0 + + CVE-2020-27222 + CVE-2021-34433 + + dependency (californium/scandium) + DTLS with x509 and/or RPK + + + + 1.0.0 -> 1.0.2 + :x: + CVE-2022-2576 + dependency (californium/scandium) + DTLS_VERIFY_PEERS_ ON_RESUMPTION_THRESHOLD > 0 + + CVE-2021-34433 + dependency (californium/scandium) + DTLS with x509 and/or RPK +