{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d325e1e1-c0b0-51c7-a230-d49d09461f08",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2",
      "type": "library",
      "group": "com.thoughtworks.xstream",
      "name": "xstream-benchmark",
      "version": "1.4.17-tuxcare.2",
      "purl": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d333e426-a434-538b-a3ac-319115858d0d",
      "id": "CVE-2020-26258",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-26258 does not affect version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark. already_fixed \u2014 CVE-2020-26258 has already been fixed in the target repository. The vendor patch commit 6740c04b217aef02d44fba26402b35e0f6f493ce is present, adding 'jdk.nashorn.internal.objects.NativeString' to the default blacklist in XStream's security framework. This prevents the Server-Side Request Forgery attack chain described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2059e7f4-5d7c-5f61-9bcf-7473fc1bb4cb",
      "id": "CVE-2020-26259",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-26259 does not affect version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark. already_fixed \u2014 XStream version 1.4.17 already contains a fix for CVE-2020-26259. The target has an even stronger defense than the original 1.4.15 fix: it denies the entire InputStream type hierarchy, which comprehensively blocks ReadAllStream$FileStream and all other malicious InputStream subclasses."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a149fc82-7aa0-5236-9300-6c194f8975be",
      "id": "CVE-2021-39139",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39139 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91f65aa7-e6be-542c-a63c-7e9262a4b89d",
      "id": "CVE-2021-39140",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39140 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fcdffca-12ea-5d4a-9338-79ea4f535b9d",
      "id": "CVE-2021-39141",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39141 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a391e55-2e69-5d15-99ad-fb9f3b588c45",
      "id": "CVE-2021-39144",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39144 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c139fab4-261a-5f88-9247-53e4a6b0adea",
      "id": "CVE-2021-39145",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39145 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99650481-113c-5feb-9a80-54e347f2d818",
      "id": "CVE-2021-39146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39146 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5725db8b-4845-513f-920f-8285448ef86d",
      "id": "CVE-2021-39147",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39147 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4efbea4b-47f3-5808-9394-2e3894931847",
      "id": "CVE-2021-39148",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39148 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5c50004-952a-5266-bcaf-38fb046dd19a",
      "id": "CVE-2021-39149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39149 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b787c782-61c7-531c-91c1-b1f9d6447a55",
      "id": "CVE-2021-39150",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39150 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1898bbee-3972-543a-ad19-81bd55c96944",
      "id": "CVE-2021-39151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39151 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4378cc21-1872-5236-83f1-8513eab77f81",
      "id": "CVE-2021-39152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39152 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b29d102-1fca-5e75-a362-4bad29cd3353",
      "id": "CVE-2021-39153",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39153 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:031f0da6-2d39-5b9f-bd38-02c64de3b77c",
      "id": "CVE-2021-39154",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39154 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5a8caf0-9854-5361-acba-83ce12d158f2",
      "id": "CVE-2021-43859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43859 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28f01ad5-3617-5818-93e9-84220110251e",
      "id": "CVE-2022-40151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40151 affects version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff242a43-18c8-56ff-9def-f7a33ebff911",
      "id": "CVE-2022-40152",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-40152 is a false positive for com.thoughtworks.xstream:xstream-benchmark 1.4.17-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55b9d6df-72c6-52c9-bacb-88559532e8e0",
      "id": "CVE-2022-41966",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41966 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdbd561f-5b79-5643-b89d-191d40937e32",
      "id": "CVE-2024-47072",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47072 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-benchmark."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7566380-05a7-57ec-999c-2f7fc1825e24",
      "id": "GHSA-3mq5-fq9h-gj7j",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-3mq5-fq9h-gj7j is a false positive for com.thoughtworks.xstream:xstream-benchmark 1.4.17-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/com.thoughtworks.xstream/xstream-benchmark@1.4.17-tuxcare.2"
    }
  ]
}