{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:085022aa-797c-5395-8022-7c8e932fd2e9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-spring",
      "version": "9.4.57.v20241219-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e3ee86e7-1cbf-5e36-a6d0-3c8c8c116df0",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a38716a-ce43-56e6-8d3f-c1eba5735d8b",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7859bae3-4895-50a9-9e46-5d9ab85da088",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e762653c-651a-5188-a035-e2f208388b4f",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f809f495-847e-53cb-8d0e-af056a0e631f",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91ebc54b-7a07-536e-9d44-69abf5fbca1b",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d077c5e2-e0bf-5c3a-88ee-95d29f6bfe29",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:952f1a2c-18f1-564e-a3bc-e26eb4893ebf",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c807687-bd9e-5dd6-955e-2a166af64c1d",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7675c6c6-9b95-50d6-a929-a7e06adce2ce",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d85b4b3-afce-582e-9d66-ab3dd54b147e",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-6763 does not affect version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-spring. fix for CVE for this version has been already backported by the original developers, so this brunch is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0ceecc6-89a2-57f1-b6e5-bf4a8b84c2c3",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f460bd40-5572-548e-b597-84dd3f20b7a9",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42539039-492f-5879-992a-2f6ad8361beb",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-5115 is fixed in version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:526b9db4-5275-5e9b-adce-cd9e91d103a9",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0c0f55e-56d6-5896-a7c7-17f3bd20b6ca",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77c69f7b-83d3-5af1-bff6-9b27aef73e1d",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:063cb6c8-5fb5-54bc-a750-04650f0abdcc",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.57.v20241219-tuxcare.2"
    }
  ]
}