The release candidates come first so if you see 4.0.2RC1 this was the first proposed release to become 4.0.2.
Affected version only shows you the version the bug was found in, it does not show if time has been spent going through the old versions to see if they are also affected. Sometimes a number of affected versions will be listed if someone has gone to the trouble of tracing back.
Yes the fix version is the release that will contain the fix.
Yes JBAS-2 looks like the versions are incorrect.