{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:63352cd8-5e1d-5f7f-89c6-e864fa91a9ce",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "5.4.36-p2+tuxcare",
      "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5609fae0-66b4-524c-8bcb-7d00c9581752",
      "id": "CVE-2017-14775",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-14775 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:722ec2b0-4569-56b0-918b-109994e1b226",
      "id": "CVE-2017-16894",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16894 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ead0d979-ea6a-59fb-9bdf-e7181d2903a3",
      "id": "CVE-2018-15133",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15133 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa3f44a0-ea92-5ad6-856a-501bc6fe81d2",
      "id": "CVE-2020-19316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-19316 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7979fe1-9f69-5357-ab94-613bffce7e43",
      "id": "CVE-2020-24941",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-24941 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0146ae6c-2279-57f6-96ec-42a1d8592d8a",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9bb533f-333c-5fa5-b2b7-5eab0608508a",
      "id": "CVE-2021-43503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43503 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb8dbee8-b3b0-50bb-8bdd-2b38a86f52b6",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.4.36-p2+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccd2c6b0-9f9a-5917-8618-e1b0117f6897",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12081543-12a8-5de7-99dd-41986d09777c",
      "id": "CVE-2022-31279",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.4.36-p2+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5e51dea-7e5f-53d1-8678-d5335d850c2e",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23d78ffa-ad9f-5345-8999-d2356f9ab31c",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:156c584c-b359-53cc-8446-9f55a407ef07",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19640d34-1c25-5906-82b8-96306f853ff8",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.4.36-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36-p4+tuxcare uses SwiftMailer, not Symfony Mailer. The CVE (GHSA-5vg9-5847-vvmq) is specific to 'how Symfony Mailer and Symfony Mime handle certain character sequences'. SwiftMailer has RFC 2822 grammar validation that should reject CRLF characters in email addresses (except as proper folding whitespace), providing a different defense mechanism than what the Laravel 12.x/13.x patch..."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd46defd-6ede-5f1a-b4bb-340573adb7b7",
      "id": "GHSA-7852-w36x-6mf6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-7852-w36x-6mf6 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7e3def7-fa28-5b79-90c1-707dab25a8e4",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.4.36-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability requires the LocalFilesystemAdapter with temporary signed URL support via temporarySignedRoute(), a feature introduced in Laravel 9+. Laravel 5.4 uses FilesystemAdapter which explicitly throws RuntimeException for local storage temporary URLs, stating 'This driver does not support creating temporary URLs.' The vulnerable c..."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f5fc385-6901-52c5-bd90-2fe84ba4a614",
      "id": "GHSA-qm5c-m76r-2hfr",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-qm5c-m76r-2hfr affects version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c79d5586-e3a1-5490-983d-4d46935e0f0a",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
    }
  ]
}