You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
|`under_investigation`| No version information available. | Reported |
599
-
|`known_affected`| No version information available. | Reported |
600
-
|`known_not_affected`| No version information available. | Not reported |
601
-
|`fixed`| The fixed component version is newer than the component version included in the scanned software. | Reported: In this case, the component is vulnerable and should be upgraded. The associated RHSA should also be reported with this CVE. |
602
-
|`fixed`| The fixed component version is older than the component version included in the scanned software. | Not reported: In this case, the component should be considered already fixed and is not vulnerable in the scanned software. |
603
-
596
+
| Product Status | Product Details | Component Details | Reporting Information |
|`under_investigation`| Only main product version information available. | No component version information available. | Reported |
599
+
|`known_affected`| Only main product version information available. | No component version information available. | Reported |
600
+
|`known_not_affected`| Only main product version information available. | No component version information available. | Not reported |
601
+
|`fixed`| Fixed on the same product stream | The fixed component version is newer than the component version included in the scanned software. | Reported: In this case, the component is vulnerable and should be upgraded. The associated RHSA should also be reported with this CVE. |
602
+
|`fixed`| Fixed on a different product stream | The fixed component version is newer than the component version included in the scanned software. ||
603
+
|`fixed`| Fixed on the same product stream | The fixed component version is older than the component version included in the scanned software. | Not reported: In this case, the component should be considered already fixed and is not vulnerable in the scanned software. |
604
+
|`fixed`| Fixed on a different product stream | The fixed component version is older than the component version included in the scanned software. ||
604
605
For the "red_hat_enterprise_linux_9:gcc" product/component pair, it is listed in the `known_affected` section.
605
606
606
607
<!-- TODO: Add CVE example with "known_not_affected" CVE-2024-43790 / vim -->
@@ -702,20 +703,20 @@ Vendors are encouraged to raise any questions regarding security data by opening
702
703
Many scanning vendors face similar challenges when reading and parsing Red Hat's security data. To check if your question
703
704
has already been asked, you can review the list of questions asked [here](https://issues.redhat.com/browse/SECDATA-862?filter=12444038).
0 commit comments