CyberzSOC

Applicability
← Back to CVE-2025-54313

CVE-2025-54313

In CISA KEV Prettier

Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.

Does it affect your version?

A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.

What each source says

Red Hat CSAF/VEX
precedence 100 · revised 2026-06-30
122 not affected
OSV.dev (incl. GHSA)
precedence 80 · revised 2026-08-12
11 affected 9 fixed
CVE List v5 (CNA container)
precedence 60 · revised 2026-02-26
4 affected

Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.

Statements (146)

Product Status Versions Remediation Source
streams_for_apache_kafka_2:com.github.streamshub-console com.github.streamshub-console as a component of streams for Apache Kafka 2 not affected vulnerable code not present no version stated vendor label: com.github.streamshub-console not applicable csaf_redhat
red_hat_openshift_dev_spaces:devspaces/dashboard-rhel9 devspaces/dashboard-rhel9 as a component of Red Hat OpenShift Dev Spaces not affected vulnerable code not present devspaces/dashboard-rhel9 not applicable csaf_redhat
red_hat_enterprise_linux_10:firefox firefox as a component of Red Hat Enterprise Linux 10 not affected vulnerable code not present no version stated vendor label: firefox not applicable csaf_redhat
red_hat_enterprise_linux_7:firefox firefox as a component of Red Hat Enterprise Linux 7 not affected vulnerable code not present no version stated vendor label: firefox not applicable csaf_redhat
red_hat_enterprise_linux_8:firefox firefox as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: firefox not applicable csaf_redhat
red_hat_enterprise_linux_9:firefox firefox as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: firefox not applicable csaf_redhat
red_hat_enterprise_linux_9:firefox-x11 firefox-x11 as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: firefox-x11 not applicable csaf_redhat
red_hat_enterprise_linux_10:firefox.src firefox.src as a component of Red Hat Enterprise Linux 10 not affected vulnerable code not present no version stated vendor label: firefox.src not applicable csaf_redhat
red_hat_enterprise_linux_7:firefox.src firefox.src as a component of Red Hat Enterprise Linux 7 not affected vulnerable code not present no version stated vendor label: firefox.src not applicable csaf_redhat
red_hat_enterprise_linux_8:firefox.src firefox.src as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: firefox.src not applicable csaf_redhat
red_hat_enterprise_linux_9:firefox.src firefox.src as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: firefox.src not applicable csaf_redhat
red_hat_enterprise_linux_10:gjs-devel gjs-devel as a component of Red Hat Enterprise Linux 10 not affected vulnerable code not present no version stated vendor label: gjs-devel not applicable csaf_redhat
red_hat_enterprise_linux_9:gjs-devel gjs-devel as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: gjs-devel not applicable csaf_redhat
red_hat_enterprise_linux_10:gjs.src gjs.src as a component of Red Hat Enterprise Linux 10 not affected vulnerable code not present no version stated vendor label: gjs.src not applicable csaf_redhat
red_hat_enterprise_linux_9:gjs.src gjs.src as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: gjs.src not applicable csaf_redhat
red_hat_enterprise_linux_10:grafana grafana as a component of Red Hat Enterprise Linux 10 not affected vulnerable code not present no version stated vendor label: grafana not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana grafana as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana not applicable csaf_redhat
red_hat_enterprise_linux_9:grafana grafana as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: grafana not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-azure-monitor grafana-azure-monitor as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-azure-monitor not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-cloudwatch grafana-cloudwatch as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-cloudwatch not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-elasticsearch grafana-elasticsearch as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-elasticsearch not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-graphite grafana-graphite as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-graphite not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-influxdb grafana-influxdb as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-influxdb not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-loki grafana-loki as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-loki not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-mssql grafana-mssql as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-mssql not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-mysql grafana-mysql as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-mysql not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-opentsdb grafana-opentsdb as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-opentsdb not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-postgres grafana-postgres as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-postgres not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-prometheus grafana-prometheus as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-prometheus not applicable csaf_redhat
red_hat_enterprise_linux_10:grafana-selinux grafana-selinux as a component of Red Hat Enterprise Linux 10 not affected vulnerable code not present no version stated vendor label: grafana-selinux not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-selinux grafana-selinux as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-selinux not applicable csaf_redhat
red_hat_enterprise_linux_9:grafana-selinux grafana-selinux as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: grafana-selinux not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-stackdriver grafana-stackdriver as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-stackdriver not applicable csaf_redhat
red_hat_enterprise_linux_10:grafana.src grafana.src as a component of Red Hat Enterprise Linux 10 not affected vulnerable code not present no version stated vendor label: grafana.src not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana.src grafana.src as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana.src not applicable csaf_redhat
red_hat_enterprise_linux_9:grafana.src grafana.src as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: grafana.src not applicable csaf_redhat
migration_toolkit_for_virtualization:migration-toolkit-virtualization/mtv-console-plugin-rhel9 migration-toolkit-virtualization/mtv-console-plugin-rhel9 as a component of Migration Toolkit for Virtualization not affected vulnerable code not present migration-toolkit-virtualization/mtv-console-plugin-rhel9 not applicable csaf_redhat
migration_toolkit_for_virtualization:mtv-candidate/mtv-console-plugin-rhel9 mtv-candidate/mtv-console-plugin-rhel9 as a component of Migration Toolkit for Virtualization not affected vulnerable code not present mtv-candidate/mtv-console-plugin-rhel9 not applicable csaf_redhat
red_hat_openshift_gitops:openshift-gitops-1/argo-rollouts-rhel8 openshift-gitops-1/argo-rollouts-rhel8 as a component of Red Hat OpenShift GitOps not affected vulnerable code not present openshift-gitops-1/argo-rollouts-rhel8 not applicable csaf_redhat
red_hat_openshift_gitops:openshift-gitops-1/argocd-extensions-rhel8 openshift-gitops-1/argocd-extensions-rhel8 as a component of Red Hat OpenShift GitOps not affected vulnerable code not present openshift-gitops-1/argocd-extensions-rhel8 not applicable csaf_redhat
red_hat_openshift_gitops:openshift-gitops-1/argocd-rhel8 openshift-gitops-1/argocd-rhel8 as a component of Red Hat OpenShift GitOps not affected vulnerable code not present openshift-gitops-1/argocd-rhel8 not applicable csaf_redhat
red_hat_openshift_gitops:openshift-gitops-1/console-plugin-rhel8 openshift-gitops-1/console-plugin-rhel8 as a component of Red Hat OpenShift GitOps not affected vulnerable code not present openshift-gitops-1/console-plugin-rhel8 not applicable csaf_redhat
red_hat_openshift_gitops:openshift-gitops-1/dex-rhel8 openshift-gitops-1/dex-rhel8 as a component of Red Hat OpenShift GitOps not affected vulnerable code not present openshift-gitops-1/dex-rhel8 not applicable csaf_redhat
red_hat_openshift_gitops:openshift-gitops-1/gitops-rhel8 openshift-gitops-1/gitops-rhel8 as a component of Red Hat OpenShift GitOps not affected vulnerable code not present openshift-gitops-1/gitops-rhel8 not applicable csaf_redhat
red_hat_openshift_gitops:openshift-gitops-1/gitops-rhel8-operator openshift-gitops-1/gitops-rhel8-operator as a component of Red Hat OpenShift GitOps not affected vulnerable code not present openshift-gitops-1/gitops-rhel8-operator not applicable csaf_redhat
red_hat_openshift_gitops:openshift-gitops-1/must-gather-rhel8 openshift-gitops-1/must-gather-rhel8 as a component of Red Hat OpenShift GitOps not affected vulnerable code not present openshift-gitops-1/must-gather-rhel8 not applicable csaf_redhat
openshift_lightspeed:openshift-lightspeed/lightspeed-console-plugin-rhel9 openshift-lightspeed/lightspeed-console-plugin-rhel9 as a component of OpenShift Lightspeed not affected vulnerable code not present openshift-lightspeed/lightspeed-console-plugin-rhel9 not applicable csaf_redhat
openshift_pipelines:openshift-pipelines/pipelines-console-plugin-rhel8 openshift-pipelines/pipelines-console-plugin-rhel8 as a component of OpenShift Pipelines not affected vulnerable code not present openshift-pipelines/pipelines-console-plugin-rhel8 not applicable csaf_redhat
openshift_pipelines:openshift-pipelines/pipelines-console-plugin-rhel9 openshift-pipelines/pipelines-console-plugin-rhel9 as a component of OpenShift Pipelines not affected vulnerable code not present openshift-pipelines/pipelines-console-plugin-rhel9 not applicable csaf_redhat
openshift_pipelines:openshift-pipelines/pipelines-hub-api-rhel8 openshift-pipelines/pipelines-hub-api-rhel8 as a component of OpenShift Pipelines not affected vulnerable code not present openshift-pipelines/pipelines-hub-api-rhel8 not applicable csaf_redhat
openshift_pipelines:openshift-pipelines/pipelines-hub-api-rhel9 openshift-pipelines/pipelines-hub-api-rhel9 as a component of OpenShift Pipelines not affected vulnerable code not present openshift-pipelines/pipelines-hub-api-rhel9 not applicable csaf_redhat
openshift_pipelines:openshift-pipelines/pipelines-hub-db-migration-rhel8 openshift-pipelines/pipelines-hub-db-migration-rhel8 as a component of OpenShift Pipelines not affected vulnerable code not present openshift-pipelines/pipelines-hub-db-migration-rhel8 not applicable csaf_redhat
openshift_pipelines:openshift-pipelines/pipelines-hub-db-migration-rhel9 openshift-pipelines/pipelines-hub-db-migration-rhel9 as a component of OpenShift Pipelines not affected vulnerable code not present openshift-pipelines/pipelines-hub-db-migration-rhel9 not applicable csaf_redhat
openshift_pipelines:openshift-pipelines/pipelines-hub-ui-rhel8 openshift-pipelines/pipelines-hub-ui-rhel8 as a component of OpenShift Pipelines not affected vulnerable code not present openshift-pipelines/pipelines-hub-ui-rhel8 not applicable csaf_redhat
openshift_pipelines:openshift-pipelines/pipelines-hub-ui-rhel9 openshift-pipelines/pipelines-hub-ui-rhel9 as a component of OpenShift Pipelines not affected vulnerable code not present openshift-pipelines/pipelines-hub-ui-rhel9 not applicable csaf_redhat
openshift_serverless:openshift-serverless-1/kn-backstage-plugins-eventmesh-rhel8 openshift-serverless-1/kn-backstage-plugins-eventmesh-rhel8 as a component of OpenShift Serverless not affected vulnerable code not present openshift-serverless-1/kn-backstage-plugins-eventmesh-rhel8 not applicable csaf_redhat
red_hat_openshift_container_platform_4:openshift4/ose-console openshift4/ose-console as a component of Red Hat OpenShift Container Platform 4 not affected vulnerable code not present openshift4/ose-console not applicable csaf_redhat
red_hat_openshift_container_platform_4:openshift4/ose-console-rhel9 openshift4/ose-console-rhel9 as a component of Red Hat OpenShift Container Platform 4 not affected vulnerable code not present openshift4/ose-console-rhel9 not applicable csaf_redhat
red_hat_jboss_enterprise_application_platform_8:org.keycloak-keycloak-parent org.keycloak-keycloak-parent as a component of Red Hat JBoss Enterprise Application Platform 8 not affected vulnerable code not present no version stated vendor label: org.keycloak-keycloak-parent not applicable csaf_redhat
red_hat_jboss_enterprise_application_platform_expansion_pack:org.keycloak-keycloak-parent org.keycloak-keycloak-parent as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack not affected vulnerable code not present no version stated vendor label: org.keycloak-keycloak-parent not applicable csaf_redhat
page 1 of 3 next →

A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.