{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8debc66b-11ec-51a7-b841-c0d993f77e33",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2",
      "type": "library",
      "group": "com.thoughtworks.xstream",
      "name": "xstream-distribution",
      "version": "1.4.17-tuxcare.2",
      "purl": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e3cfc9f2-3248-5df2-bb88-91810980923a",
      "id": "CVE-2020-26258",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-26258 does not affect version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution. already_fixed \u2014 CVE-2020-26258 has already been fixed in the target repository. The vendor patch commit 6740c04b217aef02d44fba26402b35e0f6f493ce is present, adding 'jdk.nashorn.internal.objects.NativeString' to the default blacklist in XStream's security framework. This prevents the Server-Side Request Forgery attack chain described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:028dafb9-37e7-5ced-9968-cf9d2c9d7759",
      "id": "CVE-2020-26259",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-26259 does not affect version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution. already_fixed \u2014 XStream version 1.4.17 already contains a fix for CVE-2020-26259. The target has an even stronger defense than the original 1.4.15 fix: it denies the entire InputStream type hierarchy, which comprehensively blocks ReadAllStream$FileStream and all other malicious InputStream subclasses."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:807e4b77-e5e2-5f03-984b-04fe744e7141",
      "id": "CVE-2021-39139",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39139 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f90f3ab-438b-50ae-a169-fea10d737acc",
      "id": "CVE-2021-39140",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39140 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3860f8ae-0d9d-5435-86b3-c3cb29e5e2e2",
      "id": "CVE-2021-39141",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39141 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bbf53d2-92eb-523c-b58d-560590b4652b",
      "id": "CVE-2021-39144",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39144 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63b3e8f2-f703-5972-87cb-20bcec86ad0f",
      "id": "CVE-2021-39145",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39145 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44d7ad01-23f4-593c-8d5c-4ef719d54ac2",
      "id": "CVE-2021-39146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39146 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3451b7eb-5bb5-524a-8e19-ca25a7b1bdf1",
      "id": "CVE-2021-39147",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39147 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee12e54b-e103-523d-8410-36fe61558220",
      "id": "CVE-2021-39148",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39148 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9045ffaf-08e7-5c85-ac9a-4cc856635f44",
      "id": "CVE-2021-39149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39149 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7731fbb8-1a41-5647-b7ed-f5f49d958e66",
      "id": "CVE-2021-39150",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39150 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b72ec32-c535-5a61-a92a-63d1ddcc0885",
      "id": "CVE-2021-39151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39151 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f8d9645-3ea8-5717-8178-ecdcb869205e",
      "id": "CVE-2021-39152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39152 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64d82c0f-75af-5d5f-bcb3-256f32f569b9",
      "id": "CVE-2021-39153",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39153 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdc02b3b-f864-501b-afb2-36ae3ab0b0cf",
      "id": "CVE-2021-39154",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39154 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d644578f-2f96-5905-93cb-f5a86000ceeb",
      "id": "CVE-2021-43859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43859 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be060dce-4cf3-571e-9721-112540cbeaea",
      "id": "CVE-2022-40151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40151 affects version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b3d2654-3300-5dcd-8648-f8889b7b01e5",
      "id": "CVE-2022-40152",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-40152 is a false positive for com.thoughtworks.xstream:xstream-distribution 1.4.17-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:432876ff-7c2c-5792-a60b-cfd57efc22c1",
      "id": "CVE-2022-41966",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41966 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:708d8bdd-fef8-5c63-b685-3a8b0489fedf",
      "id": "CVE-2024-47072",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47072 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-distribution."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fea43dab-7e73-5dcd-bbe8-1b8cbdb3ef06",
      "id": "GHSA-3mq5-fq9h-gj7j",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-3mq5-fq9h-gj7j is a false positive for com.thoughtworks.xstream:xstream-distribution 1.4.17-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/com.thoughtworks.xstream/xstream-distribution@1.4.17-tuxcare.2"
    }
  ]
}