Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| streams_for_apache_kafka_2:com.github.streamshub-console com.github.streamshub-console as a component of streams for Apache Kafka 2 | not affected vulnerable code not present | no version stated vendor label: com.github.streamshub-console | not applicable | csaf_redhat | |
| red_hat_openshift_dev_spaces:devspaces/dashboard-rhel9 devspaces/dashboard-rhel9 as a component of Red Hat OpenShift Dev Spaces | not affected vulnerable code not present | devspaces/dashboard-rhel9 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_10:firefox firefox as a component of Red Hat Enterprise Linux 10 | not affected vulnerable code not present | no version stated vendor label: firefox | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_7:firefox firefox as a component of Red Hat Enterprise Linux 7 | not affected vulnerable code not present | no version stated vendor label: firefox | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:firefox firefox as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: firefox | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:firefox firefox as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: firefox | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:firefox-x11 firefox-x11 as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: firefox-x11 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_10:firefox.src firefox.src as a component of Red Hat Enterprise Linux 10 | not affected vulnerable code not present | no version stated vendor label: firefox.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_7:firefox.src firefox.src as a component of Red Hat Enterprise Linux 7 | not affected vulnerable code not present | no version stated vendor label: firefox.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:firefox.src firefox.src as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: firefox.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:firefox.src firefox.src as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: firefox.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_10:gjs-devel gjs-devel as a component of Red Hat Enterprise Linux 10 | not affected vulnerable code not present | no version stated vendor label: gjs-devel | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:gjs-devel gjs-devel as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: gjs-devel | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_10:gjs.src gjs.src as a component of Red Hat Enterprise Linux 10 | not affected vulnerable code not present | no version stated vendor label: gjs.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:gjs.src gjs.src as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: gjs.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_10:grafana grafana as a component of Red Hat Enterprise Linux 10 | not affected vulnerable code not present | no version stated vendor label: grafana | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:grafana grafana as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: grafana | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:grafana grafana as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: grafana | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:grafana-azure-monitor grafana-azure-monitor as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: grafana-azure-monitor | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:grafana-cloudwatch grafana-cloudwatch as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: grafana-cloudwatch | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:grafana-elasticsearch grafana-elasticsearch as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: grafana-elasticsearch | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:grafana-graphite grafana-graphite as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: grafana-graphite | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:grafana-influxdb grafana-influxdb as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: grafana-influxdb | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:grafana-loki grafana-loki as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: grafana-loki | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:grafana-mssql grafana-mssql as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: grafana-mssql | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:grafana-mysql grafana-mysql as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: grafana-mysql | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:grafana-opentsdb grafana-opentsdb as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: grafana-opentsdb | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:grafana-postgres grafana-postgres as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: grafana-postgres | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:grafana-prometheus grafana-prometheus as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: grafana-prometheus | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_10:grafana-selinux grafana-selinux as a component of Red Hat Enterprise Linux 10 | not affected vulnerable code not present | no version stated vendor label: grafana-selinux | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:grafana-selinux grafana-selinux as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: grafana-selinux | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:grafana-selinux grafana-selinux as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: grafana-selinux | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:grafana-stackdriver grafana-stackdriver as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: grafana-stackdriver | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_10:grafana.src grafana.src as a component of Red Hat Enterprise Linux 10 | not affected vulnerable code not present | no version stated vendor label: grafana.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:grafana.src grafana.src as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | no version stated vendor label: grafana.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:grafana.src grafana.src as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: grafana.src | not applicable | csaf_redhat | |
| migration_toolkit_for_virtualization:migration-toolkit-virtualization/mtv-console-plugin-rhel9 migration-toolkit-virtualization/mtv-console-plugin-rhel9 as a component of Migration Toolkit for Virtualization | not affected vulnerable code not present | migration-toolkit-virtualization/mtv-console-plugin-rhel9 | not applicable | csaf_redhat | |
| migration_toolkit_for_virtualization:mtv-candidate/mtv-console-plugin-rhel9 mtv-candidate/mtv-console-plugin-rhel9 as a component of Migration Toolkit for Virtualization | not affected vulnerable code not present | mtv-candidate/mtv-console-plugin-rhel9 | not applicable | csaf_redhat | |
| red_hat_openshift_gitops:openshift-gitops-1/argo-rollouts-rhel8 openshift-gitops-1/argo-rollouts-rhel8 as a component of Red Hat OpenShift GitOps | not affected vulnerable code not present | openshift-gitops-1/argo-rollouts-rhel8 | not applicable | csaf_redhat | |
| red_hat_openshift_gitops:openshift-gitops-1/argocd-extensions-rhel8 openshift-gitops-1/argocd-extensions-rhel8 as a component of Red Hat OpenShift GitOps | not affected vulnerable code not present | openshift-gitops-1/argocd-extensions-rhel8 | not applicable | csaf_redhat | |
| red_hat_openshift_gitops:openshift-gitops-1/argocd-rhel8 openshift-gitops-1/argocd-rhel8 as a component of Red Hat OpenShift GitOps | not affected vulnerable code not present | openshift-gitops-1/argocd-rhel8 | not applicable | csaf_redhat | |
| red_hat_openshift_gitops:openshift-gitops-1/console-plugin-rhel8 openshift-gitops-1/console-plugin-rhel8 as a component of Red Hat OpenShift GitOps | not affected vulnerable code not present | openshift-gitops-1/console-plugin-rhel8 | not applicable | csaf_redhat | |
| red_hat_openshift_gitops:openshift-gitops-1/dex-rhel8 openshift-gitops-1/dex-rhel8 as a component of Red Hat OpenShift GitOps | not affected vulnerable code not present | openshift-gitops-1/dex-rhel8 | not applicable | csaf_redhat | |
| red_hat_openshift_gitops:openshift-gitops-1/gitops-rhel8 openshift-gitops-1/gitops-rhel8 as a component of Red Hat OpenShift GitOps | not affected vulnerable code not present | openshift-gitops-1/gitops-rhel8 | not applicable | csaf_redhat | |
| red_hat_openshift_gitops:openshift-gitops-1/gitops-rhel8-operator openshift-gitops-1/gitops-rhel8-operator as a component of Red Hat OpenShift GitOps | not affected vulnerable code not present | openshift-gitops-1/gitops-rhel8-operator | not applicable | csaf_redhat | |
| red_hat_openshift_gitops:openshift-gitops-1/must-gather-rhel8 openshift-gitops-1/must-gather-rhel8 as a component of Red Hat OpenShift GitOps | not affected vulnerable code not present | openshift-gitops-1/must-gather-rhel8 | not applicable | csaf_redhat | |
| openshift_lightspeed:openshift-lightspeed/lightspeed-console-plugin-rhel9 openshift-lightspeed/lightspeed-console-plugin-rhel9 as a component of OpenShift Lightspeed | not affected vulnerable code not present | openshift-lightspeed/lightspeed-console-plugin-rhel9 | not applicable | csaf_redhat | |
| openshift_pipelines:openshift-pipelines/pipelines-console-plugin-rhel8 openshift-pipelines/pipelines-console-plugin-rhel8 as a component of OpenShift Pipelines | not affected vulnerable code not present | openshift-pipelines/pipelines-console-plugin-rhel8 | not applicable | csaf_redhat | |
| openshift_pipelines:openshift-pipelines/pipelines-console-plugin-rhel9 openshift-pipelines/pipelines-console-plugin-rhel9 as a component of OpenShift Pipelines | not affected vulnerable code not present | openshift-pipelines/pipelines-console-plugin-rhel9 | not applicable | csaf_redhat | |
| openshift_pipelines:openshift-pipelines/pipelines-hub-api-rhel8 openshift-pipelines/pipelines-hub-api-rhel8 as a component of OpenShift Pipelines | not affected vulnerable code not present | openshift-pipelines/pipelines-hub-api-rhel8 | not applicable | csaf_redhat | |
| openshift_pipelines:openshift-pipelines/pipelines-hub-api-rhel9 openshift-pipelines/pipelines-hub-api-rhel9 as a component of OpenShift Pipelines | not affected vulnerable code not present | openshift-pipelines/pipelines-hub-api-rhel9 | not applicable | csaf_redhat | |
| openshift_pipelines:openshift-pipelines/pipelines-hub-db-migration-rhel8 openshift-pipelines/pipelines-hub-db-migration-rhel8 as a component of OpenShift Pipelines | not affected vulnerable code not present | openshift-pipelines/pipelines-hub-db-migration-rhel8 | not applicable | csaf_redhat | |
| openshift_pipelines:openshift-pipelines/pipelines-hub-db-migration-rhel9 openshift-pipelines/pipelines-hub-db-migration-rhel9 as a component of OpenShift Pipelines | not affected vulnerable code not present | openshift-pipelines/pipelines-hub-db-migration-rhel9 | not applicable | csaf_redhat | |
| openshift_pipelines:openshift-pipelines/pipelines-hub-ui-rhel8 openshift-pipelines/pipelines-hub-ui-rhel8 as a component of OpenShift Pipelines | not affected vulnerable code not present | openshift-pipelines/pipelines-hub-ui-rhel8 | not applicable | csaf_redhat | |
| openshift_pipelines:openshift-pipelines/pipelines-hub-ui-rhel9 openshift-pipelines/pipelines-hub-ui-rhel9 as a component of OpenShift Pipelines | not affected vulnerable code not present | openshift-pipelines/pipelines-hub-ui-rhel9 | not applicable | csaf_redhat | |
| openshift_serverless:openshift-serverless-1/kn-backstage-plugins-eventmesh-rhel8 openshift-serverless-1/kn-backstage-plugins-eventmesh-rhel8 as a component of OpenShift Serverless | not affected vulnerable code not present | openshift-serverless-1/kn-backstage-plugins-eventmesh-rhel8 | not applicable | csaf_redhat | |
| red_hat_openshift_container_platform_4:openshift4/ose-console openshift4/ose-console as a component of Red Hat OpenShift Container Platform 4 | not affected vulnerable code not present | openshift4/ose-console | not applicable | csaf_redhat | |
| red_hat_openshift_container_platform_4:openshift4/ose-console-rhel9 openshift4/ose-console-rhel9 as a component of Red Hat OpenShift Container Platform 4 | not affected vulnerable code not present | openshift4/ose-console-rhel9 | not applicable | csaf_redhat | |
| red_hat_jboss_enterprise_application_platform_8:org.keycloak-keycloak-parent org.keycloak-keycloak-parent as a component of Red Hat JBoss Enterprise Application Platform 8 | not affected vulnerable code not present | no version stated vendor label: org.keycloak-keycloak-parent | not applicable | csaf_redhat | |
| red_hat_jboss_enterprise_application_platform_expansion_pack:org.keycloak-keycloak-parent org.keycloak-keycloak-parent as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack | not affected vulnerable code not present | no version stated vendor label: org.keycloak-keycloak-parent | not applicable | csaf_redhat |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.