{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:862b7694-c0c0-5e08-9a64-bee9e390b18d",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "elasticsearch-java",
      "purl": "pkg:maven/co.elastic.clients/elasticsearch-java@7.17.15-tuxcare.1",
      "type": "library",
      "group": "co.elastic.clients",
      "bom-ref": "pkg:maven/co.elastic.clients/elasticsearch-java@7.17.15-tuxcare.1",
      "version": "7.17.15-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2023-49921",
      "affects": [
        {
          "ref": "pkg:maven/co.elastic.clients/elasticsearch-java@7.17.15-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bd287f40-0840-5eef-8da8-39c6d72025a6",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-49921 is a false positive for co.elastic.clients:elasticsearch-java 7.17.15-tuxcare.1. false_positive \u2014 CVE-2023-49921 is a wrong-project match. This repository is the Elasticsearch Java CLIENT library (co.elastic.clients), which provides API request/response structures for communicating with Elasticsearch servers. The CVE concerns the Elasticsearch SERVER's X-Pack Watcher component (org.elasticsearch.xpack.watcher.input.search), where search input execution results are logged at DEBUG level. The..."
      }
    },
    {
      "id": "CVE-2024-23444",
      "affects": [
        {
          "ref": "pkg:maven/co.elastic.clients/elasticsearch-java@7.17.15-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4c3b619a-46b1-5820-a6ce-dd4792bbbe17",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-23444 is a false positive for co.elastic.clients:elasticsearch-java 7.17.15-tuxcare.1. false_positive \u2014 CVE-2024-23444 is a false positive for this repository. The CVE concerns the elasticsearch-certutil CLI tool, which is part of the Elasticsearch SERVER distribution (elasticsearch/elasticsearch repository). This repository is the Elasticsearch Java CLIENT library (elasticsearch-java), a completely separate project that provides an HTTP client for connecting to Elasticsearch servers. The certuti..."
      }
    },
    {
      "id": "CVE-2024-23450",
      "affects": [
        {
          "ref": "pkg:maven/co.elastic.clients/elasticsearch-java@7.17.15-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9e2defd3-f39a-5fa5-a8ec-28273f9b478b",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-23450 is a false positive for co.elastic.clients:elasticsearch-java 7.17.15-tuxcare.1. false_positive \u2014 CVE-2024-23450 describes a vulnerability in the Elasticsearch SERVER's ingest node pipeline execution engine, where processing documents through deeply nested pipelines can crash the node. However, this repository is the Elasticsearch JAVA CLIENT (artifact: co.elastic.clients:elasticsearch-java), which is a client library for communicating with Elasticsearch servers via REST API. The client con..."
      }
    },
    {
      "id": "CVE-2024-43709",
      "affects": [
        {
          "ref": "pkg:maven/co.elastic.clients/elasticsearch-java@7.17.15-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:db87b917-8f9b-54ba-a0c7-cf8faef13c78",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-43709 affects version 7.17.15-tuxcare.1 of co.elastic.clients:elasticsearch-java."
      }
    },
    {
      "id": "CVE-2024-52979",
      "affects": [
        {
          "ref": "pkg:maven/co.elastic.clients/elasticsearch-java@7.17.15-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:380846f9-89e5-5c30-bc3b-2079c98cf553",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-52979 is a false positive for co.elastic.clients:elasticsearch-java 7.17.15-tuxcare.1. false_positive \u2014 CVE-2024-52979 concerns the Elasticsearch server's Mustache template evaluation engine, not the Elasticsearch Java Client. This repository (elasticsearch-java v7.17.15) is a client library that only constructs and sends HTTP requests containing templates to the server for evaluation. The vulnerable template evaluation code does not exist in this client - it resides in the Elasticsearch server. ..."
      }
    },
    {
      "id": "CVE-2024-52980",
      "affects": [
        {
          "ref": "pkg:maven/co.elastic.clients/elasticsearch-java@7.17.15-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:98dc6762-8149-5a44-a32c-4c24f097c022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-52980 is a false positive for co.elastic.clients:elasticsearch-java 7.17.15-tuxcare.1. false_positive \u2014 CVE-2024-52980 describes a vulnerability in the Elasticsearch SERVER's PatternBank class (org.elasticsearch.ingest.grok.PatternBank.innerForbidCircularReferences). This repository is the Elasticsearch Java API CLIENT library (co.elastic.clients:elasticsearch-java version 7.17.15), not the Elasticsearch server. The vulnerable component's code is absent from the entire repository - this is a wron..."
      }
    },
    {
      "id": "CVE-2024-52981",
      "affects": [
        {
          "ref": "pkg:maven/co.elastic.clients/elasticsearch-java@7.17.15-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7a977f00-ac73-5be5-b75c-1f4c934b090a",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-52981 is a false positive for co.elastic.clients:elasticsearch-java 7.17.15-tuxcare.1. false_positive \u2014 CVE-2024-52981 is a wrong-project match. The vulnerability concerns WKT (Well-Known Text) parsing with deeply nested GeometryCollection objects in the Elasticsearch SERVER, but this repository is the Elasticsearch Java CLIENT library. The client does not parse WKT strings\u2014it only serializes them to JSON and sends them to the server over HTTP. The vulnerable component (WKT parser with GeometryCo..."
      }
    },
    {
      "id": "CVE-2025-37727",
      "affects": [
        {
          "ref": "pkg:maven/co.elastic.clients/elasticsearch-java@7.17.15-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2e767302-33cf-5bc6-b429-bf90b7affd94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-37727 affects version 7.17.15-tuxcare.1 of co.elastic.clients:elasticsearch-java."
      }
    },
    {
      "id": "CVE-2025-37731",
      "affects": [
        {
          "ref": "pkg:maven/co.elastic.clients/elasticsearch-java@7.17.15-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0ba3b078-500b-543b-ab6a-5c4ad556148c",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-37731 is a false positive for co.elastic.clients:elasticsearch-java 7.17.15-tuxcare.1. false_positive \u2014 CVE-2025-37731 is a false positive for this repository. The CVE concerns \"Improper Authentication in Elasticsearch PKI realm,\" which is a server-side authentication mechanism in the Elasticsearch server. This repository is the Elasticsearch Java Client (co.elastic.clients:elasticsearch-java), a client library that provides API request/response wrappers for communicating with Elasticsearch serve..."
      }
    },
    {
      "id": "CVE-2025-68384",
      "affects": [
        {
          "ref": "pkg:maven/co.elastic.clients/elasticsearch-java@7.17.15-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4ae10976-de8e-59e7-a457-7b7fe3ed738b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68384 does not affect version 7.17.15-tuxcare.1 of co.elastic.clients:elasticsearch-java. not_affected \u2014 Version 7.17.15 does not contain the vulnerable component. The vulnerability exists in BufferedByteConsumer class within the rest5_client package, which was introduced after this version. The target uses the older rest_client package with Apache HttpClient 4.x, where the vulnerable code path does not exist.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-68390",
      "affects": [
        {
          "ref": "pkg:maven/co.elastic.clients/elasticsearch-java@7.17.15-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:44a5ba85-a8de-5252-bdce-fb43dece4838",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68390 does not affect version 7.17.15-tuxcare.1 of co.elastic.clients:elasticsearch-java. not_affected \u2014 Target version 7.17.15 is not affected by CVE-2025-68390. The vulnerability exists in the BufferedByteConsumer class (in rest5_client package for HttpClient 5.x support) which doesn't exist in this version. Version 7.17.15 uses the older rest_client architecture with Apache HttpClient 4.x, which has a completely different response handling mechanism (BufferedHttpEntity) without the vulnerable b...",
        "justification": "code_not_present"
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/co.elastic.clients/elasticsearch-java@7.17.15-tuxcare.1"
    }
  ]
}