{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:037f8580-1578-5f41-a731-2b915d77962b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/com.itextpdf/itextpdf@5.0.6-tuxcare.1",
      "type": "library",
      "group": "com.itextpdf",
      "name": "itextpdf",
      "version": "5.0.6-tuxcare.1",
      "purl": "pkg:maven/com.itextpdf/itextpdf@5.0.6-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ea517ef2-88ac-54e0-9201-ad283eb305bc",
      "id": "CVE-2017-9096",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-9096 is fixed in version 5.0.6-tuxcare.1 of com.itextpdf:itextpdf."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.itextpdf/itextpdf@5.0.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b72f41b4-6fe3-5e18-bac2-a1604a7b04f7",
      "id": "CVE-2021-43113",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-43113 does not affect version 5.0.6-tuxcare.1 of com.itextpdf:itextpdf. not_affected \u2014 CVE-2021-43113 affects iText 7.x series through the CompareTool and GhostscriptHelper classes, which do not exist in iText 5.0.6. The vulnerable code path was introduced in later versions and is not present in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.itextpdf/itextpdf@5.0.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65b4d531-641a-5b40-b6a8-236a89587119",
      "id": "CVE-2022-24196",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-24196 does not affect version 5.0.6-tuxcare.1 of com.itextpdf:itextpdf. Version not vulnerable (per prereq analysis); terminalized."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.itextpdf/itextpdf@5.0.6-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff2e39f8-7a62-57a6-82bc-c9fe42f83efd",
      "id": "CVE-2022-24197",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-24197 does not affect version 5.0.6-tuxcare.1 of com.itextpdf:itextpdf. Version not vulnerable (per prereq analysis); terminalized."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.itextpdf/itextpdf@5.0.6-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/com.itextpdf/itextpdf@5.0.6-tuxcare.1"
    }
  ]
}