{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:39943894-675e-500b-9b6f-b7fa657ea9b6",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1",
      "type": "library",
      "group": "org.apache.hadoop",
      "name": "hadoop-mapreduce-client-app",
      "version": "2.7.3.tuxcare.1",
      "purl": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6dee98ad-8de8-5c57-bd61-48aee95b2a56",
      "id": "CVE-2016-6811",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6811 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-mapreduce-client-app."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cbf1bde-0b26-55d1-9f72-d8fae5399a71",
      "id": "CVE-2017-15713",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-15713 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-mapreduce-client-app."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e57055bd-e53d-5ec7-8da8-3f3c2fa05376",
      "id": "CVE-2017-15718",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-15718 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-mapreduce-client-app."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61f23a18-d046-5aeb-b3be-af704a56b782",
      "id": "CVE-2017-3166",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-3166 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-mapreduce-client-app."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa3f77e5-31f6-5baa-ac06-4274264661bd",
      "id": "CVE-2017-7669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-7669 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-mapreduce-client-app."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b45b4808-9793-5b4e-836f-db34fedc467d",
      "id": "CVE-2018-11765",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11765 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-mapreduce-client-app."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edab85eb-53fc-554c-9823-c485178ca024",
      "id": "CVE-2018-11766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11766 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-mapreduce-client-app."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2ee9814-29bc-579b-baef-e65d3f2ffb35",
      "id": "CVE-2018-11768",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11768 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-mapreduce-client-app."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edb4efe2-664c-5f70-9349-29494e75e0e9",
      "id": "CVE-2018-1296",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1296 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-mapreduce-client-app."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01b5757f-80cb-587b-9019-0ac20a0e802c",
      "id": "CVE-2018-8009",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8009 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-mapreduce-client-app."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5accb0e-580c-5341-839f-8a5787a9b179",
      "id": "CVE-2018-8029",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8029 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-mapreduce-client-app."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aaffb6cb-1d62-5a82-bbc0-c7a831555f92",
      "id": "CVE-2020-9492",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9492 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-mapreduce-client-app."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4422423e-3234-5f53-8567-8c7502128d43",
      "id": "CVE-2021-25642",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-25642 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-mapreduce-client-app."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e7524b0-ddf2-5ed6-a0b2-4c4cae167e4a",
      "id": "CVE-2021-33036",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-33036 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-mapreduce-client-app."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e0a7e90-687d-5345-a1e9-63b14336578b",
      "id": "CVE-2021-37404",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-37404 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-mapreduce-client-app."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d4018eb-3fb4-5f12-92d1-c771f15b7121",
      "id": "CVE-2022-25168",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25168 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-mapreduce-client-app."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52719dc9-af2a-54b8-b802-9cab07e2e8ae",
      "id": "CVE-2022-26612",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-26612 affects version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-mapreduce-client-app."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90060a76-970b-500c-a2ff-80aca423ecd3",
      "id": "CVE-2024-23454",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23454 is fixed in version 2.7.3.tuxcare.1 of org.apache.hadoop:hadoop-mapreduce-client-app."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.hadoop/hadoop-mapreduce-client-app@2.7.3.tuxcare.1"
    }
  ]
}