Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| red_hat_openshift_distributed_tracing_3:rhosdt/tempo-gateway-opa-rhel8 rhosdt/tempo-gateway-opa-rhel8 as a component of Red Hat OpenShift distributed tracing 3 | affected | rhosdt/tempo-gateway-opa-rhel8 | out of support | csaf_redhat | |
| red_hat_openshift_distributed_tracing_3:rhosdt/tempo-gateway-rhel8 rhosdt/tempo-gateway-rhel8 as a component of Red Hat OpenShift distributed tracing 3 | affected | rhosdt/tempo-gateway-rhel8 | out of support | csaf_redhat | |
| red_hat_openshift_distributed_tracing_3:rhosdt/tempo-jaeger-query-rhel8 rhosdt/tempo-jaeger-query-rhel8 as a component of Red Hat OpenShift distributed tracing 3 | affected | rhosdt/tempo-jaeger-query-rhel8 | out of support | csaf_redhat | |
| red_hat_openshift_distributed_tracing_3:rhosdt/tempo-query-rhel8 rhosdt/tempo-query-rhel8 as a component of Red Hat OpenShift distributed tracing 3 | affected | rhosdt/tempo-query-rhel8 | out of support | csaf_redhat | |
| red_hat_openshift_distributed_tracing_3:rhosdt/tempo-rhel8 rhosdt/tempo-rhel8 as a component of Red Hat OpenShift distributed tracing 3 | affected | rhosdt/tempo-rhel8 | out of support | csaf_redhat | |
| red_hat_openshift_distributed_tracing_3:rhosdt/tempo-rhel8-operator rhosdt/tempo-rhel8-operator as a component of Red Hat OpenShift distributed tracing 3 | affected | rhosdt/tempo-rhel8-operator | out of support | csaf_redhat | |
| red_hat_ansible_automation_platform_2:automation-controller.src automation-controller.src as a component of Red Hat Ansible Automation Platform 2 | not affected vulnerable code not present | no version stated vendor label: automation-controller.src | not applicable | csaf_redhat | |
| red_hat_ansible_automation_platform_2:automation-eda-controller.src automation-eda-controller.src as a component of Red Hat Ansible Automation Platform 2 | not affected vulnerable code not present | no version stated vendor label: automation-eda-controller.src | not applicable | csaf_redhat | |
| red_hat_ansible_automation_platform_2:automation-gateway.src automation-gateway.src as a component of Red Hat Ansible Automation Platform 2 | not affected vulnerable code not present | no version stated vendor label: automation-gateway.src | not applicable | csaf_redhat | |
| red_hat_jboss_enterprise_application_platform_8:org.keycloak-keycloak-parent org.keycloak-keycloak-parent as a component of Red Hat JBoss Enterprise Application Platform 8 | not affected vulnerable code not present | no version stated vendor label: org.keycloak-keycloak-parent | not applicable | csaf_redhat | |
| red_hat_jboss_enterprise_application_platform_expansion_pack:org.keycloak-keycloak-parent org.keycloak-keycloak-parent as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack | not affected vulnerable code not present | no version stated vendor label: org.keycloak-keycloak-parent | not applicable | csaf_redhat | |
| https://github.com/vitejs/vite | affected | < 07ddc3ea3e5750f4761169064be87122f9b698f1 | vendor fix → 07ddc3ea3e5750f4761169064be87122f9b698f1 | osv | |
| https://github.com/vitejs/vite | affected | >= 0c3125833033fec4356ab4e90e806e02e8644c40, < 712cb71aa0e2a03dbf49db92043fb4ecbfc826b1 | vendor fix → 712cb71aa0e2a03dbf49db92043fb4ecbfc826b1 | osv | |
| https://github.com/vitejs/vite | affected | >= 814120f2ad387ca3d1e16c7dd403b04ca4b97f75, < 0eaadcf952062f13f6457c16f0120833783ade22 | vendor fix → 0eaadcf952062f13f6457c16f0120833783ade22 | osv | |
| https://github.com/vitejs/vite | affected | >= 051370a332df99d107365ed6beab418ef017eff6, < 98d066a35501cee393432dfabc8d8012372b8d24 | vendor fix → 98d066a35501cee393432dfabc8d8012372b8d24 | osv | |
| https://github.com/vitejs/vite | affected | >= d8461b5b4f2884105bab2175b86af4aac521cb5c, < 037f801075ec35bb6e52145d659f71a23813c48f | vendor fix → 037f801075ec35bb6e52145d659f71a23813c48f | osv | |
| https://github.com/vitejs/vite | affected | < 59673137c45ac2bcfad1170d954347c1a17ab949 | vendor fix → 59673137c45ac2bcfad1170d954347c1a17ab949 | osv | |
| vite | affected | >= 6.2.0, < 6.2.4 | vendor fix → 6.2.4 | osv GHSA-4r4m-qw57-chr8 | |
| vite | affected | >= 6.1.0, < 6.1.3 | vendor fix → 6.1.3 | osv GHSA-4r4m-qw57-chr8 | |
| vite | affected | >= 6.0.0, < 6.0.13 | vendor fix → 6.0.13 | osv GHSA-4r4m-qw57-chr8 | |
| vite | affected | >= 5.0.0, < 5.4.16 | vendor fix → 5.4.16 | osv GHSA-4r4m-qw57-chr8 | |
| vite | affected | < 4.5.11 | vendor fix → 4.5.11 | osv GHSA-4r4m-qw57-chr8 | |
| https://github.com/vitejs/vite | fixed | 07ddc3ea3e5750f4761169064be87122f9b698f1 | vendor fix → 07ddc3ea3e5750f4761169064be87122f9b698f1 | osv | |
| https://github.com/vitejs/vite | fixed | 712cb71aa0e2a03dbf49db92043fb4ecbfc826b1 | vendor fix → 712cb71aa0e2a03dbf49db92043fb4ecbfc826b1 | osv | |
| https://github.com/vitejs/vite | fixed | 0eaadcf952062f13f6457c16f0120833783ade22 | vendor fix → 0eaadcf952062f13f6457c16f0120833783ade22 | osv | |
| https://github.com/vitejs/vite | fixed | 98d066a35501cee393432dfabc8d8012372b8d24 | vendor fix → 98d066a35501cee393432dfabc8d8012372b8d24 | osv | |
| https://github.com/vitejs/vite | fixed | 037f801075ec35bb6e52145d659f71a23813c48f | vendor fix → 037f801075ec35bb6e52145d659f71a23813c48f | osv | |
| https://github.com/vitejs/vite | fixed | 59673137c45ac2bcfad1170d954347c1a17ab949 | vendor fix → 59673137c45ac2bcfad1170d954347c1a17ab949 | osv | |
| vite | fixed | 6.2.4 | vendor fix → 6.2.4 | osv GHSA-4r4m-qw57-chr8 | |
| vite | fixed | 6.1.3 | vendor fix → 6.1.3 | osv GHSA-4r4m-qw57-chr8 | |
| vite | fixed | 6.0.13 | vendor fix → 6.0.13 | osv GHSA-4r4m-qw57-chr8 | |
| vite | fixed | 5.4.16 | vendor fix → 5.4.16 | osv GHSA-4r4m-qw57-chr8 | |
| vite | fixed | 4.5.11 | vendor fix → 4.5.11 | osv GHSA-4r4m-qw57-chr8 | |
| vitejs/vite vitejs · vite | affected | >= 6.2.0, < 6.2.4 | none available | cve_cna | |
| vitejs/vite vitejs · vite | affected | >= 6.1.0, < 6.1.3 | none available | cve_cna | |
| vitejs/vite vitejs · vite | affected | >= 6.0.0, < 6.0.13 | none available | cve_cna | |
| vitejs/vite vitejs · vite | affected | >= 5.0.0, < 5.4.16 | none available | cve_cna | |
| vitejs/vite vitejs · vite | affected | < 4.5.11 | none available | cve_cna |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.