Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| https://github.com/zkoss/zk | affected | < 4271cf0b0a9a1686fafc43af169bc3768f57cba0 | vendor fix → 4271cf0b0a9a1686fafc43af169bc3768f57cba0 | osv | |
| https://github.com/zkoss/zk | affected | >= 6c6f10ad57143191b1fb21c1794cbabc504a858c, < 9b0d586e384f0962798ece209dcf30ccd9cc35f3 | vendor fix → 9b0d586e384f0962798ece209dcf30ccd9cc35f3 | osv | |
| https://github.com/zkoss/zk | affected | >= 9ed43004a2cf446d06f6003969b8807339e829b1, < 901c4a647002475d126fda878f4b3bbb2290fba9 | vendor fix → 901c4a647002475d126fda878f4b3bbb2290fba9 | osv | |
| https://github.com/zkoss/zk | affected | >= d37dc80e9414849536f12d41b5ef766d02058046, < fa2007a98b562012b42734def9373f1d5e456897 | vendor fix → fa2007a98b562012b42734def9373f1d5e456897 | osv | |
| org.zkoss.zk:zk | affected | < 8.6.4.2 | vendor fix → 8.6.4.2 | osv GHSA-6278-2q4m-cmf3 | |
| org.zkoss.zk:zk | affected | >= 9.0.0.0, < 9.0.1.3 | vendor fix → 9.0.1.3 | osv GHSA-6278-2q4m-cmf3 | |
| org.zkoss.zk:zk | affected | >= 9.5.0.0, < 9.5.1.4 | vendor fix → 9.5.1.4 | osv GHSA-6278-2q4m-cmf3 | |
| org.zkoss.zk:zk | affected | >= 9.6.0.0, < 9.6.0.2 | vendor fix → 9.6.0.2 | osv GHSA-6278-2q4m-cmf3 | |
| org.zkoss.zk:zk | affected | >= 9.6.1, < 9.6.2 | vendor fix → 9.6.2 | osv GHSA-6278-2q4m-cmf3 | |
| https://github.com/zkoss/zk | fixed | 4271cf0b0a9a1686fafc43af169bc3768f57cba0 | vendor fix → 4271cf0b0a9a1686fafc43af169bc3768f57cba0 | osv | |
| https://github.com/zkoss/zk | fixed | 9b0d586e384f0962798ece209dcf30ccd9cc35f3 | vendor fix → 9b0d586e384f0962798ece209dcf30ccd9cc35f3 | osv | |
| https://github.com/zkoss/zk | fixed | 901c4a647002475d126fda878f4b3bbb2290fba9 | vendor fix → 901c4a647002475d126fda878f4b3bbb2290fba9 | osv | |
| https://github.com/zkoss/zk | fixed | fa2007a98b562012b42734def9373f1d5e456897 | vendor fix → fa2007a98b562012b42734def9373f1d5e456897 | osv | |
| org.zkoss.zk:zk | fixed | 8.6.4.2 | vendor fix → 8.6.4.2 | osv GHSA-6278-2q4m-cmf3 | |
| org.zkoss.zk:zk | fixed | 9.0.1.3 | vendor fix → 9.0.1.3 | osv GHSA-6278-2q4m-cmf3 | |
| org.zkoss.zk:zk | fixed | 9.5.1.4 | vendor fix → 9.5.1.4 | osv GHSA-6278-2q4m-cmf3 | |
| org.zkoss.zk:zk | fixed | 9.6.0.2 | vendor fix → 9.6.0.2 | osv GHSA-6278-2q4m-cmf3 | |
| org.zkoss.zk:zk | fixed | 9.6.2 | vendor fix → 9.6.2 | osv GHSA-6278-2q4m-cmf3 | |
| n/a/n/a n/a · n/a | affected | no version stated vendor label: all versions | none available | cve_cna |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.