{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d1e448b0-405b-5452-8b46-7d253fa8a4b5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework.security",
      "name": "spring-security-cas",
      "version": "4.2.12.RELEASE-tuxcare.1",
      "purl": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:15c05fd2-67f5-5207-879e-fb7bac5caf9a",
      "id": "CVE-2007-1651",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2007-1651 does not affect version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas. already_fixed \u2014 The target repository already contains the fix for CVE-2007-1651. The upstream patch commit f5468087c2 (April 15, 2010) that removes cached DiscoveryInformation from session is present in the target's git history, plus additional security enhancements from commit 89fa771093 (July 13, 2011) that add null checking and ATTRIBUTE_LIST_KEY removal."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a16aed5d-6e4e-513a-809c-68c67657505e",
      "id": "CVE-2007-1652",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2007-1652 does not affect version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas. already_fixed \u2014 The target repository (spring-security 5.7.11.tuxcare) already contains the security fixes for CVE-2007-1652. Both defensive measures from the upstream patches are present: (1) null check rejecting requests with missing DiscoveryInformation at lines 141-144, and (2) immediate session token removal at lines 149-150. These fixes were merged via upstream commits f5468087c2 (April 2010) and 89fa771..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8e59de7-4573-57aa-83d1-412d533c87eb",
      "id": "CVE-2018-1258",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1258 affects version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee033e8c-bfcd-5743-b8f0-1bb8273f40aa",
      "id": "CVE-2019-11272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-11272 is fixed in version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25b01eb4-bc37-5aa6-9e5d-782396ee648c",
      "id": "CVE-2019-3795",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-3795 does not affect version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas. already_fixed \u2014 CVE-2019-3795 is already fixed in Spring Security 4.2.12.RELEASE. The target version contains the security patch (commit 6f02f690ac6, March 2019) that prevents insecure randomness by forcing SecureRandom auto-seeding before applying custom seeds."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c84bb43-4209-5ff9-8797-86b79b64e1b1",
      "id": "CVE-2020-5408",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5408 affects version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba9767a2-9764-5bd8-82a9-c74ff4177f1e",
      "id": "CVE-2021-22112",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22112 is fixed in version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ceaec48-b130-530b-99c9-bbb420cea7db",
      "id": "CVE-2021-22119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22119 affects version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3fbbd4c-95a0-5cb2-835f-d69057adf190",
      "id": "CVE-2022-22978",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22978 is fixed in version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cba802c8-63e2-5df6-b675-c24958880d70",
      "id": "CVE-2023-34042",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34042 affects version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd6e3f75-df5a-5a7b-ac3d-07a8f8f6dfd3",
      "id": "CVE-2024-22257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22257 is fixed in version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:348c96dc-718b-5e17-b75d-babfe88867b6",
      "id": "CVE-2024-38821",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38821 affects version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a313a17-622e-5f7a-898f-cb84840c86cf",
      "id": "CVE-2024-38827",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38827 is fixed in version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08842a09-cad1-5373-971f-c542d338d740",
      "id": "CVE-2025-22228",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22228 is fixed in version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:768a616d-34fe-5860-b120-2ed15b60e25a",
      "id": "CVE-2026-22732",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22732 affects version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6a18b1a-c9e6-5cca-9787-4e26a9bab638",
      "id": "CVE-2026-22746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22746 affects version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fc72cbc-5f40-58ab-b73a-672f72a72706",
      "id": "CVE-2026-22747",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22747 affects version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bffe36a-36a0-573a-871d-1a9ddd5b4efd",
      "id": "CVE-2026-22753",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22753 does not affect version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas. According to security advisories CVE-2026-22753 does not affect Spring-Security versions earlier than 7.0.0. This is supported by manual code inspection. CVE-2026-22753 is an access-control bypass that occurs when a user-registered PathPatternRequestMatcher.Builder bean (configured with a basePath/servlet path prefix) is silently ignored by the securityMatchers DSL, causing the security filter chain to match a different URL than the user configured. The vulnerability requires two pieces of infrastructure introduced in Spring Security 7.0.0: 1. The PathPatternRequestMatcher.Builder API itself (added in upstream commit aeb2dbc2 on 2025-08-18). 2. The wiring in HttpSecurityConfiguration.createSharedObjects() that registers this Builder as a shared object \u2014 the exact line patched by upstream commit 438c783c (the CVE fix). Neither piece exists in version 4.2.12.RELEASE."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:920c4d1e-603d-513d-b5a3-af98ccc69943",
      "id": "CVE-2026-22754",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22754 does not affect version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas. According to security advisories CVE-2026-22754 does not affect Spring-Security versions earlier than 7.0.0. This is supported by manual code inspection and proof-of-concept tests ported from the upstream fix commit. CVE-2026-22754 is an access-control bypass caused by PathPatternRequestMatcherFactoryBean.afterPropertiesSet() calling this.builder.basePath(this.basePath) and discarding the return value \u2014 PathPatternRequestMatcher.Builder is immutable/copy-on-modify, so the configured basePath was silently dropped and protected URLs (e.g., /spring/path) were left unmatched by the security filter chain. The vulnerability requires two pieces of infrastructure introduced in Spring Security 7.0.0: 1. The PathPatternRequestMatcher.Builder API (added in upstream commit 3e53cc2c4a, \"Use PathPatternRequestMatcher in config\"). 2. The PathPatternRequestMatcherFactoryBean class itself \u2014 the exact file patched by upstream commit 53bcf0d1 (the CVE fix). Neither piece exists in version 4.2.12.RELEASE. The upstream POC tests (RegexMatcher, CiRegexMatcher + AuthorizationManager variants) were ported verbatim and pass."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:647f50ef-c55c-530a-8a00-e1f9ad408407",
      "id": "CVE-2026-41003",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41003 affects version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d14f7124-55d9-509e-a684-4eb9e42cb936",
      "id": "CVE-2026-41706",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41706 does not affect version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas. not_affected \u2014 Spring Security version 4.2.12.RELEASE-tuxcare.1 is not affected by CVE-2026-41706. The vulnerable classes CookieRequestCache and CookieServerRequestCache do not exist in this version. This version uses HttpSessionRequestCache which stores redirect URLs in HTTP sessions (server-side), not in browser cookies, making the cookie-based open redirect attack vector impossible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab93fb59-7c2e-5ce7-8139-c44a8abf59a3",
      "id": "CVE-2026-47838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47838 affects version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-cas."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.security/spring-security-cas@4.2.12.RELEASE-tuxcare.1"
    }
  ]
}