{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:409a00e0-665c-5955-b2dc-657c58a5d8f1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2",
      "type": "library",
      "group": "com.thoughtworks.xstream",
      "name": "xstream-hibernate",
      "version": "1.4.17-tuxcare.2",
      "purl": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9e40d098-8675-5139-8aa5-9a15b205d858",
      "id": "CVE-2020-26258",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-26258 does not affect version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate. already_fixed \u2014 CVE-2020-26258 has already been fixed in the target repository. The vendor patch commit 6740c04b217aef02d44fba26402b35e0f6f493ce is present, adding 'jdk.nashorn.internal.objects.NativeString' to the default blacklist in XStream's security framework. This prevents the Server-Side Request Forgery attack chain described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c951307-d092-50a4-9b96-ad94beaebc9c",
      "id": "CVE-2020-26259",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-26259 does not affect version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate. already_fixed \u2014 XStream version 1.4.17 already contains a fix for CVE-2020-26259. The target has an even stronger defense than the original 1.4.15 fix: it denies the entire InputStream type hierarchy, which comprehensively blocks ReadAllStream$FileStream and all other malicious InputStream subclasses."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a19eccc-e609-546a-be9f-e021da3e861d",
      "id": "CVE-2021-39139",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39139 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c842c1ee-b8d7-58de-aa26-876d5bbe4971",
      "id": "CVE-2021-39140",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39140 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e967cbc-199b-5f21-bb6a-fe54b7ad1bec",
      "id": "CVE-2021-39141",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39141 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6ef7e60-6476-5822-8902-209b6bfc9dcb",
      "id": "CVE-2021-39144",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39144 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef8b2051-8678-5074-8dcb-1238f74aece6",
      "id": "CVE-2021-39145",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39145 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cac190c0-ee76-5fcc-a256-d307e5feacfb",
      "id": "CVE-2021-39146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39146 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24f99eb5-a45c-5301-b437-01732739016a",
      "id": "CVE-2021-39147",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39147 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ebe15bc-7937-5421-9760-81aca062b36d",
      "id": "CVE-2021-39148",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39148 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4f26589-b607-59f7-b31d-c11f7b402e36",
      "id": "CVE-2021-39149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39149 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4daef30f-5ed9-59f6-9bb9-3e46f9bd3e3b",
      "id": "CVE-2021-39150",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39150 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca06478e-931b-5fbe-8dec-d45fe27b0b85",
      "id": "CVE-2021-39151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39151 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c276ec3f-e7a5-51da-bbaf-3e46cf259d14",
      "id": "CVE-2021-39152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39152 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6946f510-cd9f-5b22-9000-535d1de8ef01",
      "id": "CVE-2021-39153",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39153 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5cb492a-f203-5c1d-b7a4-0870c814647c",
      "id": "CVE-2021-39154",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39154 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47a92466-babd-56d5-9026-390c4cd79ff5",
      "id": "CVE-2021-43859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43859 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c25d56b7-a91d-509f-a19e-a6d05e87b9ec",
      "id": "CVE-2022-40151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40151 affects version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6affc2c2-4b67-526f-a0ca-c9fc60f08c95",
      "id": "CVE-2022-40152",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-40152 is a false positive for com.thoughtworks.xstream:xstream-hibernate 1.4.17-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:862a281b-7ea6-5551-8d87-af7dae3cbd5b",
      "id": "CVE-2022-41966",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41966 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8b57aa2-5204-59a3-9b5a-fc5ce2995e92",
      "id": "CVE-2024-47072",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47072 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-hibernate."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a45b3040-f7e2-54cd-a196-87fabffeb4f1",
      "id": "GHSA-3mq5-fq9h-gj7j",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-3mq5-fq9h-gj7j is a false positive for com.thoughtworks.xstream:xstream-hibernate 1.4.17-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/com.thoughtworks.xstream/xstream-hibernate@1.4.17-tuxcare.2"
    }
  ]
}