{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:58b52886-d84f-574d-baaf-b916e73e0b08",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1",
      "type": "library",
      "group": "org.elasticsearch.plugin",
      "name": "parent-join-client",
      "version": "7.16.3-tuxcare.1",
      "purl": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:af549486-914b-5943-bad1-3929508b497b",
      "id": "CVE-2022-23708",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-23708 affects version 7.16.3-tuxcare.1 of org.elasticsearch.plugin:parent-join-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf2feced-bcdb-59cb-b8cc-a8d45abbd8b8",
      "id": "CVE-2022-23710",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-23710 is a false positive for org.elasticsearch.plugin:parent-join-client 7.16.3-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83a45c18-4b86-54f2-a39b-b838169c6443",
      "id": "CVE-2023-31417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-31417 affects version 7.16.3-tuxcare.1 of org.elasticsearch.plugin:parent-join-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:170ff930-1649-58b6-9569-3ded83a9c633",
      "id": "CVE-2023-31418",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-31418 affects version 7.16.3-tuxcare.1 of org.elasticsearch.plugin:parent-join-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3db3bb7-f34d-58c7-a066-dfc49358f710",
      "id": "CVE-2023-31419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-31419 is fixed in version 7.16.3-tuxcare.1 of org.elasticsearch.plugin:parent-join-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b022f27-ddd6-52d8-ade2-210c28824e95",
      "id": "CVE-2023-46673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46673 affects version 7.16.3-tuxcare.1 of org.elasticsearch.plugin:parent-join-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcaf32db-e277-5ff4-bdfb-c071f96b9c3b",
      "id": "CVE-2023-46674",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-46674 does not affect version 7.16.3-tuxcare.1 of org.elasticsearch.plugin:parent-join-client. not_affected \u2014 Elasticsearch 7.16.3 does not contain the ESQL datasource plugins (Parquet, ORC, Iceberg) targeted by CVE-2023-46674. The ESQL feature was introduced in Elasticsearch 8.11, released in 2023, while this target version is from 2021. The vulnerability pattern (unsafe deserialization via Hadoop Configuration) cannot manifest because the affected code paths do not exist."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d57419cf-43c2-533e-94ae-ebae4f4cb9bd",
      "id": "CVE-2023-49921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49921 affects version 7.16.3-tuxcare.1 of org.elasticsearch.plugin:parent-join-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1c69527-49ab-561e-b642-ff9acbbde285",
      "id": "CVE-2024-23444",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23444 is fixed in version 7.16.3-tuxcare.1 of org.elasticsearch.plugin:parent-join-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0b8cba0-cce8-5414-a026-275cb96dd636",
      "id": "CVE-2024-23450",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23450 affects version 7.16.3-tuxcare.1 of org.elasticsearch.plugin:parent-join-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baa3bf34-fdf0-5f3c-8baa-69bce0e10c0b",
      "id": "CVE-2024-43709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-43709 is fixed in version 7.16.3-tuxcare.1 of org.elasticsearch.plugin:parent-join-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0561ff5-1e00-5d33-972b-9bfc9b8a9762",
      "id": "CVE-2024-52979",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52979 affects version 7.16.3-tuxcare.1 of org.elasticsearch.plugin:parent-join-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:130ba7bd-9c99-5361-b96c-9e800774d3bb",
      "id": "CVE-2024-52981",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52981 affects version 7.16.3-tuxcare.1 of org.elasticsearch.plugin:parent-join-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9cfc6f0-e585-5ccc-9ce7-2d1ea7725eb2",
      "id": "CVE-2025-37727",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-37727 affects version 7.16.3-tuxcare.1 of org.elasticsearch.plugin:parent-join-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c0b0e47-8791-5840-bf2f-ab136932f65e",
      "id": "CVE-2025-37731",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-37731 affects version 7.16.3-tuxcare.1 of org.elasticsearch.plugin:parent-join-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0c7c62b-aded-5539-83e6-c15a8bd60aea",
      "id": "CVE-2025-68384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68384 does not affect version 7.16.3-tuxcare.1 of org.elasticsearch.plugin:parent-join-client. not_affected \u2014 Elasticsearch 7.16.3 does not contain the user profile feature that is vulnerable in CVE-2025-68384. The entire user profile functionality (ProfileService, UpdateProfileDataRequest, profile REST endpoints) was introduced in Elasticsearch 8.x and does not exist in this version. The vulnerability affects code that validates profile data size during updates, but since the profile update mechanism ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faba3ccf-229c-531a-9228-132353ee415b",
      "id": "CVE-2025-68390",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-68390 affects version 7.16.3-tuxcare.1 of org.elasticsearch.plugin:parent-join-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.elasticsearch.plugin/parent-join-client@7.16.3-tuxcare.1"
    }
  ]
}