{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:aefdac98-ffda-54d0-afb3-d2662d1e120c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.postgresql/postgresql@42.2.16-tuxcare.1",
      "type": "library",
      "group": "org.postgresql",
      "name": "postgresql",
      "version": "42.2.16-tuxcare.1",
      "purl": "pkg:maven/org.postgresql/postgresql@42.2.16-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:200ea360-f289-579f-9cfc-3dde97a3666d",
      "id": "CVE-2022-21724",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-21724 is fixed in version 42.2.16-tuxcare.1 of org.postgresql:postgresql."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.postgresql/postgresql@42.2.16-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d4ae173-6c49-5df7-9192-65cf95b44780",
      "id": "CVE-2022-26520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-26520 is fixed in version 42.2.16-tuxcare.1 of org.postgresql:postgresql."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.postgresql/postgresql@42.2.16-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cce82a2-baa7-5831-a324-1d3cf80377ca",
      "id": "CVE-2022-31197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-31197 affects version 42.2.16-tuxcare.1 of org.postgresql:postgresql."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.postgresql/postgresql@42.2.16-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc7564a4-f5e1-5d99-822c-5d3390dcb9fd",
      "id": "CVE-2022-41946",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41946 affects version 42.2.16-tuxcare.1 of org.postgresql:postgresql."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.postgresql/postgresql@42.2.16-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:604e47f8-39e3-5fd7-b697-a9213aada8ef",
      "id": "CVE-2024-1597",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-1597 is fixed in version 42.2.16-tuxcare.1 of org.postgresql:postgresql."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.postgresql/postgresql@42.2.16-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de7eb2a2-4d51-5dc3-912b-490fc6c29fd5",
      "id": "GHSA-673j-qm5f-xpv8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-673j-qm5f-xpv8 affects version 42.2.16-tuxcare.1 of org.postgresql:postgresql."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.postgresql/postgresql@42.2.16-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.postgresql/postgresql@42.2.16-tuxcare.1"
    }
  ]
}