Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| https://github.com/minio/minio | affected | >= 9bb0869b737df8c2eb8a1451910581dee01fc72d, < 05444a0f6af8389b9bb85280fc31337c556d4300 | vendor fix → 05444a0f6af8389b9bb85280fc31337c556d4300 | osv | |
| minio | affected | >= 2019.12.17, < 2023.03.20 | vendor fix → 2023.03.20 | osv BIT-minio-2023-28432 | |
| https://github.com/minio/minio | fixed | 05444a0f6af8389b9bb85280fc31337c556d4300 | vendor fix → 05444a0f6af8389b9bb85280fc31337c556d4300 | osv | |
| minio | fixed | 2023.03.20 | vendor fix → 2023.03.20 | osv BIT-minio-2023-28432 | |
| minio/minio minio · minio | affected | >= RELEASE.2019-12-17T23-16-33Z, < RELEASE.2023-03-20T20-16-18Z | none available | cve_cna |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.