{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f2c1f458-6325-537d-acea-89bc140afb0c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.4.5-tuxcare.4",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-starter-data-jpa",
      "version": "2.4.5-tuxcare.4",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.4.5-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:37dd6113-14c0-5742-b432-4a90f80f024d",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22965 is a false positive for org.springframework.boot:spring-boot-starter-data-jpa 2.4.5-tuxcare.4. CVE-2022-22965 (Spring4Shell) vulnerable code lives in spring-framework source, not in this repo. spring-boot 2.4.5-tuxcare.4 only pins spring-framework 5.3.6 as a declared dependency in spring-boot-dependencies/build.gradle:1568. Remediation is a routine dep-version bump in the next spring-boot release (once a spring-framework -tuxcare backport of the CVE lands), not a source-level backport in this repo -- there is no MR to raise against spring-boot. Confirmed by Patch Backporter: 'no_commits_produced, source statuses: not_applicable'. Real remediation tracked under VP 86 (spring-framework x CVE-2022-22965)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.4.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ed48a36-5df4-58d8-8572-1a6711af1656",
      "id": "CVE-2023-20873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20873 is fixed in version 2.4.5-tuxcare.4 of org.springframework.boot:spring-boot-starter-data-jpa."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.4.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d86ef8e1-6dd4-50e0-b486-3c57e43d3f38",
      "id": "CVE-2023-20883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20883 is fixed in version 2.4.5-tuxcare.4 of org.springframework.boot:spring-boot-starter-data-jpa."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.4.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4133c5c7-13b3-5c38-a12a-e2fc096d0dde",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.4.5-tuxcare.4 of org.springframework.boot:spring-boot-starter-data-jpa."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.4.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22c946ea-c748-5fda-98bb-60cdeb8fd7a6",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.4.5-tuxcare.4 of org.springframework.boot:spring-boot-starter-data-jpa."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.4.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5825c638-ca30-5ccd-ad02-e8010915bbee",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38807 affects version 2.4.5-tuxcare.4 of org.springframework.boot:spring-boot-starter-data-jpa."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.4.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56f9838c-e6f4-5ce9-b02a-6bcfe6c224fa",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.4.5-tuxcare.4 of org.springframework.boot:spring-boot-starter-data-jpa."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.4.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5409f1a1-66ff-5db8-b95d-08b7f4de5246",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.4.5-tuxcare.4 of org.springframework.boot:spring-boot-starter-data-jpa."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.4.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4219d121-53b3-551d-b6cd-dc1408cb31ba",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.4.5-tuxcare.4 of org.springframework.boot:spring-boot-starter-data-jpa."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.4.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2de86afa-e2aa-5a96-8ea2-58104143659b",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40973 is fixed in version 2.4.5-tuxcare.4 of org.springframework.boot:spring-boot-starter-data-jpa."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.4.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12306464-e62d-50b1-ab8e-800f5c813611",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40974 is fixed in version 2.4.5-tuxcare.4 of org.springframework.boot:spring-boot-starter-data-jpa."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.4.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:183c4329-0b58-5a2b-a612-454a34ef1b41",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40975 is fixed in version 2.4.5-tuxcare.4 of org.springframework.boot:spring-boot-starter-data-jpa."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.4.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fe92a4e-bc5d-5d8f-a95d-0c674059566a",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40977 is fixed in version 2.4.5-tuxcare.4 of org.springframework.boot:spring-boot-starter-data-jpa."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.4.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5d5d072-1062-59d6-8893-a72e8f47b22d",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-40992 does not affect version 2.4.5-tuxcare.4 of org.springframework.boot:spring-boot-starter-data-jpa. not_affected \u2014 Spring Boot 2.7.18 is not affected by CVE-2026-40992. The vulnerability exists in the SSL auto-configuration feature introduced in Spring Boot 3.x/4.x (controlled via spring.mail.ssl.enabled and spring.mail.ssl.bundle properties). This SSL auto-configuration feature does not exist in version 2.7.18. In 2.7.18, users must manually configure all JavaMail properties via spring.mail.properties.*, i..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.4.5-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ec38cf6-097c-5523-8345-79ecc535c8c9",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41001 is fixed in version 2.4.5-tuxcare.4 of org.springframework.boot:spring-boot-starter-data-jpa."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.4.5-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.4.5-tuxcare.4"
    }
  ]
}