{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:85251c74-d03e-5646-961a-680dacc378f3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1",
      "type": "library",
      "group": "org.apache.hadoop",
      "name": "hadoop-yarn-site",
      "version": "2.7.1.tuxcare.1",
      "purl": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4c7b111e-09af-5dcf-8d96-e22268d89b62",
      "id": "CVE-2016-3086",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-3086 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9be85849-e9b0-52eb-8b78-237e75798879",
      "id": "CVE-2016-5001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-5001 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75095208-02ac-52b1-8747-0a9326bbc505",
      "id": "CVE-2016-5393",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-5393 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:261935e2-55f4-55ee-a430-05a27d6ff103",
      "id": "CVE-2016-6811",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6811 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8493e281-1414-5559-8092-1b14899d8cdb",
      "id": "CVE-2017-15713",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-15713 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e59d9855-0122-54ce-9f9f-5501e497293a",
      "id": "CVE-2017-15718",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-15718 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49141dba-0dbd-56a8-af46-b367fca4c6d3",
      "id": "CVE-2017-3166",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-3166 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:977be3fd-e182-5299-9d0a-ec85056a14fb",
      "id": "CVE-2017-7669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-7669 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25f02b88-a108-5170-946e-08c0b26c7877",
      "id": "CVE-2018-11765",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11765 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4ab83ef-5baf-558c-ab93-6c204f29fb77",
      "id": "CVE-2018-11766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11766 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:807f108b-9f57-5b30-9f41-8a34cd77d2fc",
      "id": "CVE-2018-11768",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11768 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37bb9559-5ddb-5251-a95f-2cb169aa133b",
      "id": "CVE-2018-1296",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1296 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96a43f2e-4eaa-5237-94e1-bbcdb697710e",
      "id": "CVE-2018-8009",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8009 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d366ac49-026c-5c63-88d9-f1624592a31e",
      "id": "CVE-2018-8029",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8029 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d2f35cc-9d7a-5f50-966a-de4ae7b4d446",
      "id": "CVE-2020-9492",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9492 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea0b3ec7-2385-556e-910f-c16088b48c88",
      "id": "CVE-2021-25642",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-25642 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa93962c-e4a7-5117-8ad0-b5cedb9b6245",
      "id": "CVE-2021-33036",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-33036 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e314911-6a6c-5cea-97b9-6ca6e8adc5ef",
      "id": "CVE-2021-37404",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-37404 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a23a2caf-69b0-5da6-b51a-1b0b1b2ce5ec",
      "id": "CVE-2022-25168",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25168 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e88986e-653f-5451-835c-f001f515a501",
      "id": "CVE-2022-26612",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-26612 affects version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98f4ef08-4a29-5ac4-8834-66d13bd73ca9",
      "id": "CVE-2024-23454",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23454 is fixed in version 2.7.1.tuxcare.1 of org.apache.hadoop:hadoop-yarn-site."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.hadoop/hadoop-yarn-site@2.7.1.tuxcare.1"
    }
  ]
}