{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c36b4d01-31f2-535c-8ab3-e2f3ff8fb984",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty.aggregate",
      "name": "jetty-all",
      "version": "9.4.57.v20241219-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d0a75bc6-fc9e-51d7-b0d7-72b7c4b86f15",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd05dd62-f458-5a3f-b641-2623b88405f7",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afcac120-fb3a-510e-af8f-f2e6ab40df51",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55f6b60b-f6f9-5ec1-a6b5-cc667691007c",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b815bbbb-8a93-54bf-8b6c-25865f694121",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89773f58-9481-5c45-8c48-a6993f911e53",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0113dcfb-2643-5991-aa1e-02aef8fe4042",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86e271e2-1870-580e-883a-d8983c3b39f7",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5127b541-c559-50f1-a315-bfb0f876186a",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1369c6e-c135-5b5c-af9a-4826ee810b8b",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14797bd7-e8f8-537d-a1e2-3e3793bb4431",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-6763 does not affect version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all. fix for CVE for this version has been already backported by the original developers, so this brunch is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abd97260-7fd6-576f-a1a8-d21c30163883",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c30fd2d-c676-550a-af82-545738d21b57",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d6bac08-58fb-55a3-be96-e368a9f30069",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-5115 is fixed in version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c25ef74-b4a9-5c67-b647-36e8c8a423e3",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36bf91fa-7a6d-5f8f-9aac-706aa91310fa",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30c5a74c-2ce9-5b13-bcba-15723a06a0bf",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:479525bb-af95-5961-a5ed-8687c82e0de9",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.57.v20241219-tuxcare.2"
    }
  ]
}