{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1ef36ed2-b0de-5b56-87a2-74ac87c8d439",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-bom",
      "version": "9.4.57.v20241219-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5257f064-c199-59e7-a68c-bef602ccf2dc",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4804aba8-fc0e-5267-8fad-3d342c5730c7",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c68eee1f-873c-5b10-87ce-2dcd665d1bc0",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b33bab2b-2fdf-567f-b243-e184b9fe970a",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c42b563c-9c4a-571f-b097-40320b7b1461",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e870669-04b1-58a0-8e4d-c180c7fd8377",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8921b5a7-c599-542d-8820-47f9a9c5e8f2",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d26ed813-70aa-5c65-944b-5b6399d0e7bc",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82a37488-9db1-56c1-b254-530e2cfa030f",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87325cfa-159c-5cdf-8690-19340a79e8ba",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a8edd23-4848-5676-8605-9e944d0ff626",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-6763 does not affect version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-bom. fix for CVE for this version has been already backported by the original developers, so this brunch is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84286df2-0998-54c7-8208-1a4e77deb7e2",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95a4e3c1-6fed-5680-980b-bafe70a78f75",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2530387e-0eaa-585b-aac5-aa7a028b2d32",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-5115 is fixed in version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4852d54-c536-5db8-9e9d-91092e6585c4",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a8e3ba2-b2f7-5325-ac8c-d0bf10af90a1",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b9545f0-5e1f-568f-930e-340513b9f4fb",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1dafeee-3535-535a-b5ec-06240cdcf5a2",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.57.v20241219-tuxcare.2"
    }
  ]
}