Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| https://github.com/octobercms/library | affected | < 016a297b1bec55d2e53bc889458ed2cb5c3e9374 | vendor fix → 016a297b1bec55d2e53bc889458ed2cb5c3e9374 | osv | |
| https://github.com/octobercms/library | affected | < 5bd1a28140b825baebe6becd4f7562299d3de3b9 | vendor fix → 5bd1a28140b825baebe6becd4f7562299d3de3b9 | osv | |
| https://github.com/octobercms/october | affected | >= 24d95a208bf4a0840d7b631a87ad1ce3fb4a5ed3, < 54ddc1dfea4db70190e34ce76df3053306596403 | vendor fix → 54ddc1dfea4db70190e34ce76df3053306596403 | osv | |
| https://github.com/octobercms/october | affected | >= 61e49d9e0b5f7e5323353f254d4ff12905bbe573, <= 61e49d9e0b5f7e5323353f254d4ff12905bbe573 | none available | osv | |
| https://github.com/octobercms/october | affected | >= d5a93e3b61c6587828b52ad81ad100cbf6459f9c, < 54ddc1dfea4db70190e34ce76df3053306596403 | vendor fix → 54ddc1dfea4db70190e34ce76df3053306596403 | osv | |
| https://github.com/octobercms/october | affected | >= 7ecf05138263e8aff3bb8913e270976405704b69, <= 7ecf05138263e8aff3bb8913e270976405704b69 | none available | osv | |
| october/system | affected | < 1.0.472 | vendor fix → 1.0.472 | osv GHSA-mxr5-mc97-63rc | |
| october/system | affected | >= 1.1.1, < 1.1.5 | vendor fix → 1.1.5 | osv GHSA-mxr5-mc97-63rc | |
| https://github.com/octobercms/library | fixed | 016a297b1bec55d2e53bc889458ed2cb5c3e9374 | vendor fix → 016a297b1bec55d2e53bc889458ed2cb5c3e9374 | osv | |
| https://github.com/octobercms/library | fixed | 5bd1a28140b825baebe6becd4f7562299d3de3b9 | vendor fix → 5bd1a28140b825baebe6becd4f7562299d3de3b9 | osv | |
| https://github.com/octobercms/october | fixed | 54ddc1dfea4db70190e34ce76df3053306596403 | vendor fix → 54ddc1dfea4db70190e34ce76df3053306596403 | osv | |
| october/system | fixed | 1.0.472 | vendor fix → 1.0.472 | osv GHSA-mxr5-mc97-63rc | |
| october/system | fixed | 1.1.5 | vendor fix → 1.1.5 | osv GHSA-mxr5-mc97-63rc | |
| octobercms/october octobercms · october | affected | >= 1.0.471, < 1.0.472 | none available | cve_cna | |
| octobercms/october octobercms · october | affected | >= 1.1.1, < 1.1.5 | none available | cve_cna |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.