{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:622852d9-a300-5cff-89c9-d1b6868ac0d1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1",
      "type": "library",
      "group": "com.thoughtworks.xstream",
      "name": "xstream-parent",
      "version": "1.4.17-tuxcare.1",
      "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f37ab048-8931-5241-8bb7-9e84daf6934d",
      "id": "CVE-2020-26258",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-26258 does not affect version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent. already_fixed \u2014 CVE-2020-26258 has already been fixed in the target repository. The vendor patch commit 6740c04b217aef02d44fba26402b35e0f6f493ce is present, adding 'jdk.nashorn.internal.objects.NativeString' to the default blacklist in XStream's security framework. This prevents the Server-Side Request Forgery attack chain described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8627eefe-2624-54d9-ac83-568840cef9e1",
      "id": "CVE-2020-26259",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-26259 does not affect version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent. already_fixed \u2014 XStream version 1.4.17 already contains a fix for CVE-2020-26259. The target has an even stronger defense than the original 1.4.15 fix: it denies the entire InputStream type hierarchy, which comprehensively blocks ReadAllStream$FileStream and all other malicious InputStream subclasses."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f270ca8-4f3b-5e5b-a78d-147127d8d93d",
      "id": "CVE-2021-39139",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39139 is fixed in version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46e3fd64-8847-5b0a-859b-344fb4e3da3f",
      "id": "CVE-2021-39140",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39140 is fixed in version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa049ab4-a7f4-5abf-bf5d-c9117229d95b",
      "id": "CVE-2021-39141",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39141 is fixed in version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d92f1bc9-420d-565c-8c4a-c75a2770c2c6",
      "id": "CVE-2021-39144",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39144 is fixed in version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f6cc772-df3c-5b7d-be38-e6486c6a576c",
      "id": "CVE-2021-39145",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39145 is fixed in version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b963a499-9e9f-5b01-8855-838e5ac09572",
      "id": "CVE-2021-39146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39146 is fixed in version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f922f0e1-f246-53d1-a2b7-c5fb3f3e8e6a",
      "id": "CVE-2021-39147",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39147 is fixed in version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9645b31c-11ab-5880-8c77-38ac867a8ff2",
      "id": "CVE-2021-39148",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39148 is fixed in version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c16ad8a5-bd4a-57da-8ee5-05119872b1ff",
      "id": "CVE-2021-39149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39149 is fixed in version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b31dc16-ed18-5068-9aa2-6da4742f6bfe",
      "id": "CVE-2021-39150",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39150 is fixed in version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7e2fb1f-3518-5637-937c-360017f04b7c",
      "id": "CVE-2021-39151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39151 is fixed in version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6dbeb96b-c5ec-510a-bcd1-a0a4ef8a7e58",
      "id": "CVE-2021-39152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39152 is fixed in version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:473ddfb1-01fe-5b37-8b4a-e12a72217308",
      "id": "CVE-2021-39153",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39153 is fixed in version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4d9b7f0-3cda-5d91-b857-e2d8e99e4d7c",
      "id": "CVE-2021-39154",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-39154 is fixed in version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f439f9c5-5f51-5097-b471-483e85411725",
      "id": "CVE-2021-43859",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-43859 affects version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a4be3b5-c648-596e-b6fb-0bcc11eec6dd",
      "id": "CVE-2022-40151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40151 affects version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:680bae24-1eb2-5d81-90fe-c7152b893db2",
      "id": "CVE-2022-40152",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-40152 is a false positive for com.thoughtworks.xstream:xstream-parent 1.4.17-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e9894c2-1979-5a29-b7fc-d491e6d7b637",
      "id": "CVE-2022-41966",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41966 is fixed in version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f35e558e-4fb0-51d7-9826-9cafc0f4df6d",
      "id": "CVE-2024-47072",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-47072 affects version 1.4.17-tuxcare.1 of com.thoughtworks.xstream:xstream-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38c227b3-72e2-5708-87a8-a1f98a2a77d6",
      "id": "GHSA-3mq5-fq9h-gj7j",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-3mq5-fq9h-gj7j is a false positive for com.thoughtworks.xstream:xstream-parent 1.4.17-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.1"
    }
  ]
}