{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:351edb3c-999b-5dbd-9151-a4cb78b4ff39",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-hazelcast",
      "version": "9.4.57.v20241219-tuxcare.1",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a7b51193-adbb-50eb-82da-8d0c53cd143e",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0a97ee9-d288-59da-b7b2-f4ba58672751",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d2a21ef-53ff-5b32-92bb-f71cbc159656",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d7e0ac2-f542-5844-836d-0ed08b5154ce",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:046e8f44-7b32-5714-8976-06fafd19eaa9",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:523c77f8-1039-5121-bf3d-31262ef5554d",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a2ea7e2-8f33-5362-8338-c31206e67240",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:557f0ef7-5e5d-57a9-aaf0-1c335f4d5880",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c82b55e-190f-561f-87c1-f791b6b9ebe5",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aead9997-d9e2-578b-8887-9bfa497dfea4",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e062175-5e1c-52f5-a1a9-be7c0a70378d",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-6763 does not affect version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-hazelcast. fix for CVE for this version has been already backported by the original developers, so this brunch is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0d2188d-6184-5fe4-bf6d-54f49670b91f",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d50da042-9b5e-58f6-b183-96ccfb686535",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c1bf2ea-b2c4-56a6-a8d6-0e33c9f646ae",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-5115 is fixed in version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ff3891d-b008-5a13-92c5-13e44f1dc719",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fa9a438-85ab-5e86-ad8e-d4204c394fbb",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2eb72467-d173-5894-ae79-acfd61b76ddd",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1ae5c87-d53e-5c52-aee4-6cbe9ff98add",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.57.v20241219-tuxcare.1"
    }
  ]
}