Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
Each line is one product that two or more sources describe differently. Same identifier means they both named it the same way; linked identifier means they named it differently and meet at a package URL or CPE both assert. This is recorded rather than resolved: a vendor saying "not affected" where an ecosystem says "affected" is a fact about the disclosure, and flattening it would hide the more useful half.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| red_hat_fuse_7:spring-data-commons spring-data-commons as a component of Red Hat Fuse 7 | affected | no version stated vendor label: spring-data-commons | none available | csaf_redhat | |
| red_hat_jboss_fuse_6:spring-data-commons spring-data-commons as a component of Red Hat JBoss Fuse 6 | not affected vulnerable code not present | no version stated vendor label: spring-data-commons | not applicable | csaf_redhat | |
| red_hat_jboss_fuse_integration_service_2:spring-data-commons spring-data-commons as a component of Red Hat JBoss Fuse Integration Service 2 | not affected vulnerable code not present | no version stated vendor label: spring-data-commons | not applicable | csaf_redhat | |
| red_hat_mobile_application_platform_4:spring-data-commons.src spring-data-commons.src as a component of Red Hat Mobile Application Platform 4 | not affected vulnerable code not present | no version stated vendor label: spring-data-commons.src | not applicable | csaf_redhat | |
| https://github.com/apache/ignite | affected | >= fceebf26559068eac36b7395a7c6d51229c33469, <= 86e110c750a340dc9be2d396415f0b80d7ed8813 | none available | osv | |
| https://github.com/apache/ignite | affected | >= 5fc2cd053467e65872f796e11e3edd2e6017d80d, <= f54fc36cc29533ea0ea49eacc345b7f769491bf8 | none available | osv | |
| https://github.com/spring-projects/spring-data-commons | affected | <= f386cd6e47d018c2f7640869bf5595797e3f74c0 | none available | osv | |
| https://github.com/spring-projects/spring-data-commons | affected | >= d5cad6c27f765587a3976620324153352058a4a7, <= 8ddb7cefe1fb0ba075dbbdc7035ab7e2a5c75c19 | none available | osv | |
| https://github.com/spring-projects/spring-data-commons | affected | >= dc8583795871a09d78a15b075935a6cada57d597, <= 70ac316b400937d7e1dff71c1605a4205fc818bd | none available | osv | |
| https://github.com/spring-projects/spring-data-rest | affected | <= f56485d92daceaca47e050d15f0088265852d7d8 | none available | osv | |
| https://github.com/spring-projects/spring-data-rest | affected | >= 93a2c589c5efc9e550b15103ba707c2b60f8725c, <= f916233f410b9d27e2ddb23de4c9ff1e29af29b5 | none available | osv | |
| org.springframework.data:spring-data-commons | affected | >= 1.13.0, < 1.13.11 | vendor fix → 1.13.11 | osv GHSA-4fq3-mr56-cg6r | |
| org.springframework.data:spring-data-commons | affected | >= 2.0.0, < 2.0.6 | vendor fix → 2.0.6 | osv GHSA-4fq3-mr56-cg6r | |
| org.springframework.data:spring-data-commons | fixed | 1.13.11 | vendor fix → 1.13.11 | osv GHSA-4fq3-mr56-cg6r | |
| org.springframework.data:spring-data-commons | fixed | 2.0.6 | vendor fix → 2.0.6 | osv GHSA-4fq3-mr56-cg6r | |
| Spring by Pivotal/Spring Framework Spring by Pivotal · Spring Framework | affected | Versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions | none available | cve_cna |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.