{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ccdece59-10c8-5e30-b4f0-4ec16a32a313",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5",
      "type": "library",
      "group": "org.apache.pulsar",
      "name": "pulsar-functions-runtime-all",
      "version": "3.2.4-tuxcare.5",
      "purl": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:62a82bf4-7520-5d7c-9343-fa1f823eee7e",
      "id": "CVE-2007-1420",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2007-1420 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2007-1420 concerns MySQL SERVER (version 5.x before 5.0.36) and its internal filesort function and information_schema query processing. The target repository is Apache Pulsar 3.2.4, a distributed pub-sub messaging platform. This is a wrong-project match - Pulsar does not contain MySQL server code."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44652ad8-ffa1-542c-8520-f1b2fd07cb6d",
      "id": "CVE-2007-2691",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2007-2691 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2007-2691 concerns MySQL privilege checking for RENAME TABLE SQL statements. The target repository is Apache Pulsar 3.2.4-tuxcare.1, a distributed pub-sub messaging platform, not MySQL. Apache Pulsar is a fundamentally different product (messaging system vs relational database) and contains no MySQL server source code. The MySQL references found are only client connectors (Debezium, Canal) ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d5ff187-dc66-5706-b56a-b11f9f0da1bc",
      "id": "CVE-2007-5925",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2007-5925 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2007-5925 concerns MySQL server's InnoDB storage engine (ha_innodb.cc), but the target repository is Apache Pulsar version 3.2.4-tuxcare.1, a distributed pub-sub messaging platform. This is a wrong-project match. No MySQL server code or InnoDB engine code exists in the Pulsar repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee36f2ea-cc7c-5125-b60d-2d6e6812e35e",
      "id": "CVE-2009-0819",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2009-0819 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2009-0819 affects MySQL Server's internal XPath processing (sql/item_xmlfunc.cc). The target repository is Apache Pulsar 3.2.4, a Java-based pub-sub messaging platform. Pulsar contains only MySQL JDBC client libraries (mysql-connector-java 8.0.30) for connecting to MySQL databases. The vulnerable server-side XPath processing code does not exist in this repository. This is a wrong-project ma..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd8a01eb-dce5-52d8-ad34-c92a0ada2661",
      "id": "CVE-2009-4028",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2009-4028 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2009-4028 is a wrong-project match. The vulnerability affects MySQL's native C library code (vio_verify_callback in viosslfactories.c) which is not present in Apache Pulsar. Pulsar uses mysql-connector-java 8.0.11, a pure Java JDBC driver that does not contain or use the vulnerable native MySQL C code."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f58ad54-6cc8-504f-9b1d-24f1e7ab0dc4",
      "id": "CVE-2010-1621",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2010-1621 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2010-1621 concerns MySQL 5.1 server code (specifically the mysql_uninstall_plugin function in sql/sql_plugin.cc). The target repository is Apache Pulsar 3.2.4, a distributed pub-sub messaging system, which is a completely different product. While the repository contains MySQL client libraries (mysql-connector-java, debezium-connector-mysql) as dependencies for connecting TO external MySQL d..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85df181a-7ffd-56c6-b776-858a291ceb75",
      "id": "CVE-2010-1626",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2010-1626 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2010-1626 concerns MySQL server's DROP TABLE implementation for MyISAM storage engine. The target repository is Apache Pulsar (a distributed pub-sub messaging platform), not MySQL. Pulsar does not contain MySQL server code - only client libraries (mysql-connector-java, debezium-connector-mysql) for connecting to external MySQL instances. The vulnerable component (MySQL server MyISAM DROP TA..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c2c9480-bddd-5446-863d-e94798dc9487",
      "id": "CVE-2010-3677",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2010-3677 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar 3.2.4 is not affected by CVE-2010-3677. This CVE targets MySQL SERVER code (mysqld daemon's query execution engine), while Pulsar is a pub-sub messaging platform that uses MySQL only as an external data source via JDBC client libraries. Pulsar does not contain MySQL server code, does not process SQL queries itself, and cannot reach the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e7ddb1f-8647-57d9-8297-13b8a61a3e46",
      "id": "CVE-2010-3682",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2010-3682 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2010-3682 is a wrong-project match. The advisory concerns Oracle MySQL 5.1/5.0 database server (C++ codebase), while the target repository is Apache Pulsar 3.2.4, a Java-based distributed messaging platform. The vulnerable MySQL server code (Item_singlerow_subselect::store function) is not present in this repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af92c7de-29ba-58b8-b06f-1ad47044db8f",
      "id": "CVE-2012-6612",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2012-6612 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 CVE-2012-6612 affects Apache Solr server components (UpdateRequestHandler for XSLT and XPathEntityProcessor) in versions before 4.1. This repository is Apache Pulsar 3.2.4, which is a different product. Pulsar contains a Solr connector that uses Solr 8.11.3 as a client library dependency, but does not contain or implement the vulnerable server-side components. The vulnerability pattern does not..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b1e1f99-b715-5b4c-918b-591e90c4756c",
      "id": "CVE-2013-6397",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2013-6397 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2013-6397 is a wrong-project match. The CVE concerns Apache Solr server code (SolrResourceLoader, XSLT response writer), but this repository is Apache Pulsar, a messaging platform. Pulsar contains only a Solr client connector (pulsar-io/solr) that uses the Solr client library (solr-solrj) to send documents to external Solr servers. The vulnerable server-side code path (directory traversal i..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdc0324a-641f-5956-b1a1-76d354041dfa",
      "id": "CVE-2013-6407",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2013-6407 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar is not affected by CVE-2013-6407. This CVE concerns a vulnerability in Apache Solr server's UpdateRequestHandler for XML (versions before 4.1), which allows XXE attacks. Pulsar is a completely different Apache project (distributed pub-sub messaging platform) and does not contain any Solr server code. While Pulsar includes a connector module (pulsar-io-solr) that integrates with So..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f1fa90d-bc57-5bbb-a508-fa7766460f0e",
      "id": "CVE-2013-6408",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2013-6408 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar 3.2.4 is not affected by CVE-2013-6408. This CVE targets the DocumentAnalysisRequestHandler in Apache Solr server (versions before 4.3.1). Pulsar's codebase contains only a Solr client connector (pulsar-io/solr) that sends data to external Solr servers; it does not implement any Solr server components. The vulnerable server-side XML parsing code does not exist in this repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65cfe742-3eb7-5140-a62e-a06bf5b1d2d3",
      "id": "CVE-2014-0001",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0001 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2014-0001 targets the MySQL/MariaDB C/C++ client library (client/mysql.cc), but this repository is Apache Pulsar 3.2.4, a distributed messaging platform. The affected component does not exist in this repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35772fd3-5a96-5df1-a3c5-2774ee2d1ba4",
      "id": "CVE-2014-8180",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-8180 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2014-8180 concerns 'MongoDB on Red Hat Satellite 6' (a systems management product with MongoDB server authentication vulnerability), while this repository is Apache Pulsar 3.2.4 (a distributed pub-sub messaging platform). Pulsar contains only MongoDB CLIENT code (pulsar-io-mongo connector using mongodb-driver-reactivestreams:4.1.2) for connecting TO MongoDB servers, not MongoDB SERVER code ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9192ac66-8555-5ada-9be3-760ff1e7ff9a",
      "id": "CVE-2015-2325",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2015-2325 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2015-2325 is a wrong-project match. The advisory concerns the PCRE (Perl Compatible Regular Expressions) C library, but the target repository is Apache Pulsar 3.2.4-tuxcare.1, a Java-based distributed messaging system that does not use, bundle, or depend on PCRE in any way."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abc5e8a6-2b2c-5d6b-8368-2d07067bd52b",
      "id": "CVE-2015-2575",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2015-2575 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 CVE-2015-2575 affects MySQL Connector/J version 5.1.34 and earlier. Target repository (Apache Pulsar 3.2.4-tuxcare.1) uses mysql-connector-java version 8.0.30, which is far outside the affected version range. No vulnerable versions exist as vendored, bundled, or declared dependencies. The target is not affected by this CVE."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d19c721a-150e-5974-986f-b3d027abb31c",
      "id": "CVE-2015-3414",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2015-3414 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. already_fixed \u2014 CVE-2015-3414 affects SQLite before version 3.8.9. Apache Pulsar uses sqlite-jdbc version 3.42.0.0, which bundles SQLite 3.42.0. This version already contains the fix for the collation-sequence name dequoting vulnerability. Pulsar's own codebase does not implement SQL parsing or collation dequoting logic; it relies on the sqlite-jdbc driver, which includes the patched SQLite library."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7085c4b-bd35-5992-bcfd-74aecd6e5136",
      "id": "CVE-2015-3415",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2015-3415 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 CVE-2015-3415 affects SQLite versions before 3.8.9 due to improper comparison operator implementation in CHECK clauses. The target repository (Apache Pulsar 3.2.4) uses SQLite only as a runtime dependency through org.xerial:sqlite-jdbc:3.42.0.0, which bundles SQLite 3.42.0 - a version released approximately 8 years after the fix. The vulnerable code (sqlite3VdbeExec in vdbe.c) does not exist in..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9694cb1-17d4-5aab-820f-2f8179c0bacc",
      "id": "CVE-2015-3416",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2015-3416 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar 3.2.4 is not affected by CVE-2015-3416. The vulnerability exists in SQLite's printf.c source code (sqlite3VXPrintf function), which is not present in the Pulsar repository. Pulsar uses sqlite-jdbc 3.42.0.0 as a Maven dependency, which bundles SQLite 3.42.0 - a version released in 2023 that is far newer than SQLite 3.8.9 (the version that fixed this vulnerability in 2015). The vuln..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8eebdcc-1d15-5acf-a657-c6583bbe1953",
      "id": "CVE-2015-3717",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2015-3717 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 The Pulsar repository does not contain the vulnerable SQLite printf C source code. CVE-2015-3717 affects SQLite's internal printf implementation (printf.c), which exists only in the sqlite-jdbc dependency binary, not in Pulsar's source code. Additionally, the sqlite-jdbc version (3.42.0.0, using SQLite 3.42.0 from 2023) already contains fixes for this 2015 vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c29a31e-8f33-52ff-a804-5def9c271525",
      "id": "CVE-2015-5895",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2015-5895 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar 3.2.4-tuxcare.1 is not affected by CVE-2015-5895. Pulsar uses SQLite via the org.xerial:sqlite-jdbc dependency (currently version 3.42.0.0, which bundles SQLite 3.42.0). CVE-2015-5895 affects SQLite versions before 3.8.10.2. Historical analysis shows that when Pulsar first introduced SQLite support in May 2020, it used version 3.8.11.2, which was already newer than the fixed versi..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5545c077-c579-5df9-9a4b-76f0a591beea",
      "id": "CVE-2015-6607",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2015-6607 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 CVE-2015-6607 affects SQLite before version 3.8.9. Apache Pulsar 3.2.4-tuxcare.1 uses sqlite-jdbc 3.42.0.0 (which bundles SQLite 3.42.0), far newer than the vulnerable version. Historical analysis confirms Pulsar has never used a vulnerable SQLite version since SQLite support was first added in May 2020 with version 3.8.11.2 (already post-fix). The vulnerable code does not exist in the target r..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8962e651-e900-5c2b-9a77-adcc0dfb747d",
      "id": "CVE-2015-8795",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2015-8795 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2015-8795 concerns XSS vulnerabilities in Apache Solr's Admin UI web application (specifically analysis.js and schema-browser.js). This repository is Apache Pulsar 3.2.4, a distributed messaging platform, not Apache Solr. The affected component (Solr Admin UI) is not present in the Pulsar repository. Pulsar only uses Solr's client library (solr-solrj) as a dependency for its data connector,..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:029075a1-f5aa-5e99-a4bb-5f532cdba3b7",
      "id": "CVE-2015-8796",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2015-8796 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2015-8796 is a false positive for this repository. The CVE concerns Apache Solr's Admin UI (webapp/web/js/scripts/schema-browser.js), but this repository is Apache Pulsar 3.2.4, a completely different project. While Pulsar uses the Solr Java client library (solr-solrj) as a dependency for its I/O connector, the vulnerable component (Admin UI JavaScript) is part of the Solr server distributi..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20a50077-7e7f-5140-9488-6c2195145088",
      "id": "CVE-2015-8797",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2015-8797 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2015-8797 is a false positive match. The CVE concerns Apache Solr's Admin UI (a search platform), but the target repository is Apache Pulsar (a distributed messaging platform). These are completely different Apache projects. The target contains only a Solr client connector (pulsar-io/solr) which uses Solr's client library to send data to external Solr servers, but does not bundle or vendor ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa41951d-5ff0-5e03-b350-8622095df682",
      "id": "CVE-2016-0610",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2016-0610 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2016-0610 concerns MySQL/MariaDB InnoDB storage engine. The target repository is Apache Pulsar 3.2.4, a distributed pub-sub messaging platform. This is a wrong-project match - Pulsar does not contain MySQL/MariaDB server code or the InnoDB storage engine."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a1ee3b3-9532-5cf9-894e-0264672e16bd",
      "id": "CVE-2016-0616",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2016-0616 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2016-0616 affects Oracle MySQL/MariaDB SERVER's query optimizer component. The target repository is Apache Pulsar 3.2.4, a distributed pub-sub messaging platform. Pulsar contains only JDBC client libraries (mariadb-java-client 2.7.5, mysql-connector-java 8.0.11) as dependencies, which are client-side drivers that connect TO MySQL/MariaDB servers. The vulnerable component (MySQL server-side ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3307ce8-e8a7-5cb7-b71a-808297071820",
      "id": "CVE-2016-6153",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-6153 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar 3.2.4-tuxcare.1 is not affected by CVE-2016-6153. The vulnerability exists in SQLite's native C code (os_unix.c), which is not present in the Pulsar repository. Pulsar only uses SQLite as a runtime dependency (sqlite-jdbc 3.42.0.0), and does not vendor or bundle SQLite source code. Additionally, the dependency version bundles SQLite 3.42.0, which is significantly newer than the fi..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5df7bdfb-375d-5ef9-b0b8-c4057cc6beb2",
      "id": "CVE-2016-6494",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2016-6494 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2016-6494 is a false positive for this repository. The CVE concerns the MongoDB database shell executable (mongo/mongosh) and its .dbshell history file permissions. This repository is Apache Pulsar 3.2.4, a distributed pub-sub messaging platform - a completely different product. The only MongoDB-related component found is a connector module (pulsar-io/mongo) that uses the MongoDB Java drive..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9f6e885-4d3e-5913-bfef-cf963ead07db",
      "id": "CVE-2017-10989",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2017-10989 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar 3.2.4 is not affected by CVE-2017-10989. The repository uses sqlite-jdbc 3.42.0.0 (bundling SQLite 3.42.0), which is not vulnerable. CVE-2017-10989 only affects SQLite versions through 3.19.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab82ea6a-fe3e-576a-8f79-f81f5e75bbbc",
      "id": "CVE-2017-15365",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2017-15365 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2017-15365 is a wrong-project match. The vulnerability affects MariaDB/Percona XtraDB Cluster database server code (sql/event_data_objects.cc), specifically server-side DDL replication and ACL checking ordering in clustered environments. This repository is Apache Pulsar 3.2.4, a distributed messaging platform. While Pulsar contains I/O connectors that can connect to MariaDB databases as a c..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2330a60-f774-5f76-8c50-713e903a9499",
      "id": "CVE-2017-15945",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2017-15945 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2017-15945 is a false positive for this repository. The CVE concerns Gentoo installation scripts for MySQL/MariaDB/Percona database servers, while this repository is Apache Pulsar (a distributed messaging platform). The affected component code is absent from the entire repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94f6960a-aa3d-5fe3-8a8e-e0e08c5d8b05",
      "id": "CVE-2017-3163",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2017-3163 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2017-3163 concerns Apache Solr's server-side Index Replication HTTP API vulnerability. The target repository is Apache Pulsar 3.2.4, a different Apache project. Pulsar contains only a client-side Solr I/O connector (pulsar-io/solr) that uses Solr client libraries to write data TO external Solr servers. The affected component (Solr's Index Replication server-side handler code) is entirely ab..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f902fd3-92d6-5dc5-9267-62bdef065b3e",
      "id": "CVE-2017-3164",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2017-3164 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. already_fixed \u2014 CVE-2017-3164 affects Apache Solr versions 1.3 to 7.6 (inclusive). The target repository (Apache Pulsar 3.2.4-tuxcare.1) has already been patched by upgrading the Solr dependency from the vulnerable version 7.5.0 to the current non-vulnerable version 8.11.3. The patch commit (855ee939a1) that originally upgraded Solr to 8.6.0 is present in the git history and is an ancestor of the current HEAD,..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1195ab89-da54-533d-9bd7-c462f8925b30",
      "id": "CVE-2017-3302",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2017-3302 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2017-3302 concerns libmysqlclient.so (the native C client library for MySQL/MariaDB), which is not present in the Apache Pulsar repository. Pulsar uses mysql-connector-java 8.0.30, a pure Java JDBC driver that is a completely different implementation and does not use the native libmysqlclient.so library. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1554b6d3-713b-5565-8722-5a7a1153bc17",
      "id": "CVE-2018-11802",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-11802 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 CVE-2018-11802 affects Apache Solr server's authorization bypass when proxying requests between nodes. The target repository is Apache Pulsar 3.2.4, which contains a Solr I/O connector module that acts solely as a Solr CLIENT. Pulsar does not implement Solr server functionality, request proxying, or authorization logic. The vulnerable code path does not exist in Pulsar's codebase. Additionally,..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87994712-f40b-5203-b1ae-a153d373f408",
      "id": "CVE-2018-1308",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-1308 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 CVE-2018-1308 affects Apache Solr's DataImportHandler, a server-side component that Pulsar never uses or includes. Pulsar is a Solr client using only the solr-solrj library. The vulnerable code (DataImportHandler with XXE in dataConfig parameter) exists in the separate solr-dataimporthandler artifact, which is not a Pulsar dependency. Although the patch upgraded Solr from 7.5.0 to 8.6.0 (and ta..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2525e9f4-1920-53b4-ac1c-810f3ebb4de7",
      "id": "CVE-2018-20346",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-20346 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar 3.2.4 is not affected by CVE-2018-20346. The repository uses sqlite-jdbc version 3.42.0.0, which is 17 major versions after the fix version (3.25.3). Additionally, Pulsar's JDBC SQLite sink does not use the FTS3 (Full-Text Search) extension at all, and provides no mechanism for arbitrary SQL execution. The attack vector requiring FTS3 shadow table manipulation and FTS3 queries can..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef9e0053-8ab3-549e-b7fb-7613e9689bdb",
      "id": "CVE-2018-20505",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-20505 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 CVE-2018-20505 affects SQLite 3.25.2 from December 2018, which allows denial of service crashes when queries are executed on tables with malformed PRIMARY KEYs. The target repository (Apache Pulsar 3.2.4-tuxcare.1) uses SQLite via the sqlite-jdbc 3.42.0.0 dependency, which bundles SQLite 3.42.0 from May 2023. The vulnerable code path exists in SQLite's internal C library, not in Pulsar's Java c..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84027abf-1096-534e-9d01-8d29376cb66f",
      "id": "CVE-2018-20506",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-20506 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar 3.2.4 with sqlite-jdbc 3.42.0.0 is not affected by CVE-2018-20506. The vulnerability requires SQLite's FTS3 extension, which Pulsar does not use. Additionally, the SQLite library version (3.42.0) is much newer than the minimum fixed version (3.25.3)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb001e76-91eb-5b44-a5d6-a7a28a8415bd",
      "id": "CVE-2018-8740",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-8740 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 The target repository (Apache Pulsar 3.2.4-tuxcare.1) uses sqlite-jdbc version 3.42.0.0, which bundles SQLite 3.42.0. This version is well beyond the vulnerable version range specified in CVE-2018-8740 (SQLite through 3.22.0). The vulnerability exists in SQLite's C code (build.c and prepare.c) which is not present in this repository, and the dependency uses a patched version that was released y..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:197cf8e0-dafb-5462-a6ae-8907d1fcaf72",
      "id": "CVE-2019-0193",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-0193 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. already_fixed \u2014 The target repository (Apache Pulsar 3.2.4-tuxcare.1) previously contained a vulnerable Apache Solr dependency (version 7.5.0, CVE-2019-0193) but has been fixed via dependency upgrade. The patch commit 855ee939a1 upgraded Solr from 7.5.0 to 8.6.0, and subsequent upgrades reached the current version 8.11.3. All versions >= 8.2.0 contain the fix that requires explicit opt-in (enable.dih.dataConfi..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c5d8d93-1fac-50fc-a82c-efce5cf929dd",
      "id": "CVE-2019-12401",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-12401 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 The target (Apache Pulsar 3.2.4-tuxcare.1) is not affected by CVE-2019-12401. The vulnerability exists in Apache Solr's server-side XML update handler, which processes XML documents with DOCTYPE and ENTITY declarations. Pulsar uses Solr only as a client library (solr-solrj version 8.11.3) and does not include or execute the vulnerable server component. The solr-core dependency, which contains t..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:935da995-912f-508c-836e-02a8e1167e3b",
      "id": "CVE-2019-17571",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-17571 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. already_fixed \u2014 The target Apache Pulsar 3.2.4 has already mitigated CVE-2019-17571 through comprehensive migration to log4j2 (version 2.18.0) and explicit removal of log4j 1.2 dependencies. While pulsar-io/kafka/pom.xml lacks the specific exclusions added by the upstream patch (removed in commit a95154976e when switching from kafka-schema-registry to kafka-schema-registry-client), this does not introduce the ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:195e3e3d-cff4-5b67-a655-975b5833f6ba",
      "id": "CVE-2019-19645",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-19645 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 CVE-2019-19645 affects SQLite's alter.c implementation (through version 3.30.1). The target repository (Apache Pulsar) does not contain any SQLite C source code - the vulnerable alter.c file does not exist in this repository. Pulsar uses SQLite only as a declared dependency via sqlite-jdbc:3.42.0.0, which includes SQLite 3.42.0 (much newer than the affected range). The vulnerable code path cann..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7b1bbc6-6b69-556f-b897-427e1ab6e30c",
      "id": "CVE-2019-19646",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-19646 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. already_fixed \u2014 Apache Pulsar 3.2.4 uses sqlite-jdbc version 3.42.0.0, which bundles SQLite 3.42.0. This version is well beyond the affected range (SQLite \u2264 3.30.1) specified in CVE-2019-19646. The fix for this vulnerability was incorporated into SQLite versions released after 3.30.1, and the bundled SQLite 3.42.0 (released May 2023) already contains the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d4df5d3-f6a8-57c2-8c02-8dda74c952b7",
      "id": "CVE-2020-11655",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11655 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar 3.2.4-tuxcare.1 is not affected by CVE-2020-11655. The vulnerability exists in SQLite's C implementation (AggInfo object initialization in window-function query parsing), which is not present in Pulsar's codebase. Pulsar uses SQLite only as a declared dependency (org.xerial:sqlite-jdbc 3.42.0.0) for its JDBC connector, and the connector architecture does not accept or execute wind..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f1bb752-7150-542e-b94e-52de75ca9ec2",
      "id": "CVE-2020-11656",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11656 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar 3.2.4 is not affected by CVE-2020-11656 (SQLite ALTER TABLE use-after-free). Pulsar uses SQLite only as a runtime dependency (sqlite-jdbc 3.42.0.0), and the embedded SQLite version (3.42.0) is well outside the affected range (through 3.31.1). No vulnerable SQLite source code exists in the Pulsar repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:983a602a-bb66-5d67-90c3-2eb213a39918",
      "id": "CVE-2020-13434",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13434 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. already_fixed \u2014 The target repository (Apache Pulsar 3.2.4-tuxcare.1) already contains the fix for CVE-2020-13434. The vulnerability exists in SQLite's native library (integer overflow in sqlite3_str_vappendf), not in Pulsar's code. The target uses sqlite-jdbc version 3.42.0.0, which bundles SQLite 3.42.0, well beyond the affected range (SQLite \u2264 3.32.0). The fix was introduced in upstream commit ac41cfe35f (u..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18905350-75e6-5827-8f8b-a0e4f7969b12",
      "id": "CVE-2020-13435",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13435 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 The target repository (Apache Pulsar 3.2.4) is not affected by CVE-2020-13435. The vulnerable SQLite C code (sqlite3ExprCodeTarget in expr.c) does not exist in the Pulsar repository. Pulsar uses SQLite only as an external Maven dependency via sqlite-jdbc 3.42.0.0, which bundles SQLite version 3.42.0 - much newer than the affected versions (through 3.32.0) and already contains the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb4551e4-96e6-575a-a624-e45c777ddcd8",
      "id": "CVE-2020-13630",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13630 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar 3.2.4-tuxcare.1 is not affected by CVE-2020-13630. While Pulsar depends on sqlite-jdbc (version 3.42.0.0), the JDBC connector implementation does not use SQLite's FTS3 (Full Text Search) functionality or the snippet() function. The vulnerability requires executing FTS3 queries with snippet() to trigger the use-after-free in fts3EvalNextRow, but Pulsar's JDBC sink only generates ba..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b08c2a4-fbab-5542-97fa-7238c4796ac0",
      "id": "CVE-2020-13631",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13631 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar is not affected by CVE-2020-13631. The vulnerability concerns SQLite's ALTER TABLE RENAME operations on virtual tables, but Pulsar's JDBC connector does not perform any ALTER TABLE or RENAME operations. Additionally, the sqlite-jdbc dependency version 3.42.0.0 (containing SQLite 3.42.0) already includes the fix, as it is well after the vulnerable version (< 3.32.0)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65dcd8e9-7508-543b-9e4b-c1c68116fcab",
      "id": "CVE-2020-13632",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13632 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar is not affected by CVE-2020-13632. The vulnerability exists in SQLite's native C code (ext/fts3/fts3_snippet.c) which is not present in the Pulsar repository. Pulsar only uses SQLite as an external JDBC dependency (sqlite-jdbc 3.42.0.0), and does not vendor or bundle SQLite source code."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4004ec2e-4112-5ea5-9c01-64b6e06ea8a2",
      "id": "CVE-2020-13941",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13941 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar is not affected by CVE-2020-13941. The vulnerability exists in Apache Solr's server-side ReplicationHandler component, which Pulsar never invokes. Pulsar uses Solr only as a client (via solr-solrj) to write documents, not as a server. The vulnerable code path does not exist in Pulsar's architecture. Additionally, the target has already upgraded its Solr dependency to version 8.11...."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69782e28-9c2b-56ba-b89b-531b146b1785",
      "id": "CVE-2020-15358",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-15358 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. already_fixed \u2014 The target repository (Apache Pulsar 3.2.4-tuxcare.1) already contains the fix for CVE-2020-15358. The SQLite JDBC dependency has been upgraded to version 3.42.0.0, which includes SQLite library version 3.42.0 - well above the minimum fixed version of 3.32.3. The original fix commit (ac41cfe35f) that upgraded from vulnerable version 3.8.11.2 to 3.36.0.3 is an ancestor of the current HEAD, and a..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f16cb509-e2b0-573c-bced-ad260131cfd9",
      "id": "CVE-2020-28912",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-28912 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2020-28912 concerns MariaDB Server's Windows named pipe security descriptors. The target repository is Apache Pulsar (a distributed messaging platform), not MariaDB Server. The only MariaDB reference is a JDBC client library dependency (mariadb-java-client:2.7.5), which is CLIENT code for connecting TO MariaDB servers and does not contain the server-side named pipe handling code that is vul..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:771e84fb-1803-5a65-82d4-d8abe26e2f25",
      "id": "CVE-2021-27905",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-27905 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 CVE-2021-27905 affects Apache Solr's ReplicationHandler component, which does not exist in the Pulsar codebase. Pulsar uses Solr only as a client library to send data to external Solr servers. The vulnerable server-side ReplicationHandler code is not deployed, used, or exposed by Pulsar. The patches show dependency upgrades (Solr 8.6.3 to 8.11.3) but contain no source code changes because the v..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:129b9bea-31e2-53f3-9e55-de4475609fd5",
      "id": "CVE-2021-29262",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-29262 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. already_fixed \u2014 The target repository Apache Pulsar 3.2.4-tuxcare.1 is NOT vulnerable to CVE-2021-29262. The vulnerability affects Apache Solr versions prior to 8.8.2, but the target uses Solr version 8.11.3 as a Maven dependency, which is well above the fixed version threshold. The fix was originally applied via commit 76fc2fbc9801da5232cd4ba32d25298b74d460db on 2022-01-19 (upgrading from 8.6.3 to 8.11.1), an..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9690842d-2072-5931-a297-c6a3c1b36a30",
      "id": "CVE-2021-29943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-29943 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar 3.2.4-tuxcare.1 is not affected by CVE-2021-29943. This CVE concerns Apache Solr's internal server-to-server authentication mechanism (ConfigurableInternodeAuthHadoopPlugin) that forwards distributed requests between Solr cluster nodes. Pulsar's Solr connector is a CLIENT that sends requests TO Solr using the SolrJ library; it never runs Solr servers, configures inter-node authent..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:224173d3-fc53-5bd5-bc3d-8aa5de14752b",
      "id": "CVE-2021-32036",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-32036 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar v3.2.4 is not affected by CVE-2021-32036. This CVE concerns MongoDB Server's command processing implementation, specifically the 'features' command handling. Pulsar contains only MongoDB client libraries (mongodb-driver-reactivestreams v4.1.2) used for connecting TO MongoDB databases, but does not contain any MongoDB Server code. The vulnerable code path (MongoDB Server's features..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d28a24bc-3803-5b2e-931e-4fe17ce5f205",
      "id": "CVE-2021-44548",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-44548 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar 3.2.4-tuxcare.1 is not affected by CVE-2021-44548. This CVE targets Apache Solr's server-side DataImportHandler component, which Pulsar does not use. Pulsar's Solr connector is a client-only integration that uses solr-solrj to send documents to external Solr servers via HTTP/SolrCloud. The vulnerable code path (UNC path input to DataImportHandler triggering SMB network calls) does..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c674de24-3b3d-5888-8455-515475fef7cc",
      "id": "CVE-2021-46666",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-46666 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 CVE-2021-46666 affects MariaDB server's query optimizer, not the MariaDB JDBC client library. Apache Pulsar uses only mariadb-java-client version 2.7.5 as a JDBC client dependency to connect to external MariaDB servers. The vulnerable code (query optimizer performing HAVING-to-WHERE clause pushdown) exists only in MariaDB server and is not present in Pulsar's codebase."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a57fce8-a9d6-5a7d-9d65-83b3fdbfbb2f",
      "id": "CVE-2021-46667",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-46667 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2021-46667 is a false positive for this repository. The CVE affects MariaDB server code (sql_lex.cc) which is not present in Apache Pulsar. The repository only contains a MariaDB JDBC client library as a dependency, which is a separate product from the MariaDB server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3ef0052-3014-5313-bc31-fa518cce646e",
      "id": "CVE-2021-46669",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-46669 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar 3.2.4-tuxcare.1 is not affected by CVE-2021-46669. This CVE concerns a use-after-free vulnerability in MariaDB server's convert_const_to_int function (part of SQL processing internals). Pulsar only contains a JDBC client connector (mariadb-java-client v2.7.5) that sends SQL queries to external MariaDB servers. The vulnerable code path does not exist in Pulsar's codebase."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3995921-468f-5571-a06b-e87684f67a2c",
      "id": "CVE-2022-27385",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-27385 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2022-27385 concerns MariaDB Server (database engine), but this repository is Apache Pulsar (messaging platform). The vulnerable component Used_tables_and_const_cache::used_tables_and_const_cache_join exists only in MariaDB Server's C++ codebase and is not present in this repository. Pulsar has a dependency on mariadb-java-client (JDBC driver), which is a separate library unaffected by this ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6839762-a270-54b4-a790-2dd39bfe9821",
      "id": "CVE-2022-27449",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-27449 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2022-27449 concerns MariaDB Server (a C++ database server), while the target repository is Apache Pulsar (a Java messaging platform). The target only depends on mariadb-java-client (a JDBC client library), which does not contain any MariaDB server code or the vulnerable component sql/item_func.cc. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6d68de5-5ec9-52b0-8e05-124f12aa605d",
      "id": "CVE-2022-31621",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-31621 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2022-31621 concerns MariaDB Server's mariabackup utility, but the target repository is Apache Pulsar (a distributed messaging platform), not MariaDB Server. The affected component (extra/mariabackup/ds_xbstream.cc) does not exist in this repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:257cac47-1203-56db-9149-fcc5634ec5cf",
      "id": "CVE-2022-31622",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-31622 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2022-31622 concerns MariaDB Server's mariabackup utility, but the target repository is Apache Pulsar (a distributed messaging platform). The vulnerable component (extra/mariabackup/ds_compress.cc and create_worker_threads function) does not exist in this repository. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fbba25f-b82d-5d01-a8ba-91d081084cad",
      "id": "CVE-2022-31623",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-31623 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2022-31623 concerns MariaDB Server (specifically mariabackup in extra/mariabackup/ds_compress.cc), but this repository is Apache Pulsar, a distributed messaging platform. The affected component (MariaDB Server) is not present in this repository. The only MariaDB reference is mariadb-java-client v2.7.5, a pure Java JDBC client library for connecting to external MariaDB databases, which is a ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:715a4541-a349-56f4-85a2-02d4227b51f1",
      "id": "CVE-2022-31624",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-31624 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2022-31624 is a false positive for this repository. The vulnerability affects MariaDB Server's server_audit plugin (plugin/server_audit/server_audit.c), but this repository is Apache Pulsar 3.2.4-tuxcare.1, a Java-based distributed messaging platform. The affected MariaDB server component code is completely absent from this repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7607a6b-1cad-57f7-8223-3bfa51f3a408",
      "id": "CVE-2022-32531",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-32531 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. already_fixed \u2014 CVE-2022-32531 affects Apache BookKeeper Java Client versions before 4.14.6 and version 4.15.0. The target repository (Apache Pulsar 3.2.4) uses BookKeeper 4.16.6 as a dependency, which is well beyond the fixed versions (4.14.6 and 4.15.1). The vulnerability has been addressed through dependency version upgrades, with the fix first introduced in commit c28444c071 (upgrade to 4.15.1) and maintai..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c91421b-bde5-53da-b968-656ff5d489c5",
      "id": "CVE-2022-35737",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-35737 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. already_fixed \u2014 CVE-2022-35737 has been fixed in the target repository. The vulnerability affects SQLite versions before 3.39.2, but the target uses sqlite-jdbc version 3.42.0.0 (which bundles SQLite 3.42.0), well above the fix threshold."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f0d1e39-9bd5-5d9c-8907-f68c9e5b729c",
      "id": "CVE-2023-25194",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-25194 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. already_fixed \u2014 Apache Pulsar 3.2.4 has already applied the fix for CVE-2023-25194 by upgrading its kafka-client dependency to version 3.4.0. The fix commit ca0b25ecba is present in the repository history and is an ancestor of the current HEAD (f69529d946). The vulnerability was in the Apache Kafka Connect library's SASL JAAS configuration processing, which allowed JNDI injection via JndiLoginModule. Kafka Con..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94f4f205-3fd5-5fcc-8850-db6feaacb7c1",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-44487 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. already_fixed \u2014 CVE-2023-44487 (HTTP/2 Rapid Reset) has been fixed in the target repository through dependency upgrades. The target uses Jetty 9.4.54.v20240208 and Netty 4.1.111.Final, both versions higher than the minimum patched versions (Jetty 9.4.53, Netty 4.1.100) that address the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ec310d1-d9bd-5910-9da4-c910c9881e11",
      "id": "CVE-2023-5157",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-5157 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2023-5157 affects MariaDB Server, but this repository is Apache Pulsar. The affected component (MariaDB server network handling code) is absent from the entire repository. Pulsar only contains the MariaDB JDBC client library as a declared dependency, which is a different component that does not include server-side network listening code."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90186a02-8238-5577-8c91-1ba952b55f40",
      "id": "CVE-2023-7104",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-7104 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 CVE-2023-7104 is a heap-based buffer overflow vulnerability in SQLite's session extension (sessionReadRecord function). While Apache Pulsar 3.2.4-tuxcare.1 uses sqlite-jdbc version 3.42.0.0 (which bundles SQLite 3.42.0 in the affected version range), the target is NOT AFFECTED because Pulsar does not use SQLite's session extension at all. The session extension requires explicit activation via A..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4db6d218-64c2-5652-a387-c11699f7de0d",
      "id": "CVE-2024-31141",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-31141 affects version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85e425c2-0573-5b3b-b5de-b66e5888016a",
      "id": "CVE-2024-56128",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-56128 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar 3.2.4 depends on kafka-clients 3.4.0 which contains the CVE-2024-56128 vulnerability in Kafka's SCRAM server implementation. However, Pulsar is NOT AFFECTED because it never executes the vulnerable code path. Pulsar only uses kafka-clients as a CLIENT (KafkaConsumer/KafkaProducer) for Kafka source/sink connectors, and uses Kerberos/GSSAPI (not SCRAM) for its own authentication. Th..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2678959f-5adb-5b5b-ad8c-323a225f6f19",
      "id": "CVE-2025-23015",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-23015 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar is not affected by CVE-2025-23015. This CVE concerns a privilege escalation vulnerability in Apache Cassandra's server-side authorization system. Pulsar is a different product (a distributed messaging platform) that uses the Cassandra Java client driver to connect to external Cassandra databases as a data sink. The vulnerable code (Cassandra's authorization logic for system resour..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07ca7f6a-1810-5b0c-a4d5-170e3b3d741c",
      "id": "CVE-2025-24814",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-24814 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar 3.2.4-tuxcare.1 is not affected by CVE-2025-24814. The vulnerability affects Apache Solr server-side components (FileSystemConfigSetService, core creation, config file parsing with <lib> tags). Pulsar uses Solr only as a client library (solr-solrj) to connect to external Solr servers. The vulnerable server-side functionality does not exist in Pulsar's production code path. The sol..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c07a767c-1bfe-5ccf-9c39-a6d9f889b2e0",
      "id": "CVE-2025-27817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27817 affects version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1eb21cac-e30b-52a7-b940-d9f70940079a",
      "id": "CVE-2025-27818",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27818 affects version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70523153-7eff-5c18-8cbf-ffa67ff1351d",
      "id": "CVE-2025-27819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27819 affects version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c45b17f-362e-5963-97a9-7f9650e233a2",
      "id": "CVE-2025-6965",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-6965 does not affect version 3.2.4-tuxcare.5 of org.apache.pulsar:pulsar-functions-runtime-all. not_affected \u2014 Apache Pulsar 3.2.4-tuxcare.1 uses sqlite-jdbc version 3.42.0.0, which contains CVE-2025-6965 (SQLite aggregate term memory corruption). However, Pulsar's usage of SQLite is limited to INSERT, UPDATE, DELETE, and UPSERT operations through the pulsar-io-jdbc-sqlite sink. The vulnerability requires executing SELECT queries with aggregate functions (COUNT, SUM, AVG, etc.) where the aggregate term ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37268b46-601e-5236-a609-4d75a7a30b9b",
      "id": "CVE-2026-3494",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-3494 is a false positive for org.apache.pulsar:pulsar-functions-runtime-all 3.2.4-tuxcare.5. false_positive \u2014 CVE-2026-3494 describes a vulnerability in MariaDB server's audit plugin, but the target repository is Apache Pulsar (a distributed messaging platform), not MariaDB server. The repository only contains MariaDB client JDBC driver code for database connectivity, not the MariaDB server or its audit plugin. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.pulsar/pulsar-functions-runtime-all@3.2.4-tuxcare.5"
    }
  ]
}