39
39
"status" : " affected"
40
40
},
41
41
{
42
- "range" : " vers:semver />=2.9|<=4.1" ,
42
+ "range" : " vers:generic />=2.9|<=4.1" ,
43
43
"status" : " affected"
44
44
}
45
45
]
48
48
"ref" : " urn:cdx:e4c3eedc-4978-470c-ad02-6ffff63738ff/1#product-JKL" ,
49
49
"versions" : [
50
50
{
51
- "range" : " vers:semver />=4.5|<=5.0" ,
51
+ "range" : " vers:generic />=4.5|<=5.0" ,
52
52
"status" : " affected"
53
53
}
54
54
]
74
74
}
75
75
],
76
76
"analysis" : {
77
- "state" : " not_affected"
77
+ "state" : " not_affected" ,
78
+ "justification" : " code_not_present" ,
79
+ "response" : [" will_not_fix" ],
80
+ "detail" : " These versions of Product ABC are not affected by the vulnerability. Class with vulnerable code was removed before shipping."
78
81
},
79
82
"affects" : [
80
83
{
81
84
"ref" : " urn:cdx:cbb2cd68-2857-43b8-a10b-e8c03d277d18/1#product-ABC" ,
82
85
"versions" : [
83
86
{
84
- "range" : " vers:semver />=1.0|<=2.3" ,
87
+ "range" : " vers:generic />=1.0|<=2.3" ,
85
88
"status" : " unaffected"
86
89
},
87
90
{
88
91
"version" : " 2.5" ,
89
92
"status" : " unaffected"
90
93
},
91
94
{
92
- "range" : " vers:semver />=2.7|<=2.8" ,
95
+ "range" : " vers:generic />=2.7|<=2.8" ,
93
96
"status" : " unaffected"
94
97
},
95
98
{
96
99
"version" : " 4.2" ,
97
100
"status" : " unaffected"
98
101
}
99
102
]
100
- },
103
+ }
104
+ ]
105
+ },
106
+ {
107
+ "id" : " CVE-2021-44228" ,
108
+ "source" : {
109
+ "name" : " NVD" ,
110
+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2021-44228"
111
+ },
112
+ "ratings" : [
113
+ {
114
+ "source" : {
115
+ "name" : " NVD" ,
116
+ "url" : " https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/CR:X/IR:X/AR:X/MAV:X/MAC:X/MPR:X/MUI:X/MS:X/MC:N/MI:N/MA:N&version=3.1"
117
+ },
118
+ "score" : 0.0 ,
119
+ "severity" : " none" ,
120
+ "method" : " CVSSv31" ,
121
+ "vector" : " AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/CR:X/IR:X/AR:X/MAV:X/MAC:X/MPR:X/MUI:X/MS:X/MC:N/MI:N/MA:N"
122
+ }
123
+ ],
124
+ "analysis" : {
125
+ "state" : " not_affected" ,
126
+ "justification" : " code_not_present" ,
127
+ "response" : [" will_not_fix" ],
128
+ "detail" : " These versions of Product JKL are not affected by the vulnerability. Log4j was not included in those versions at all."
129
+ },
130
+ "affects" : [
101
131
{
102
132
"ref" : " urn:cdx:e4c3eedc-4978-470c-ad02-6ffff63738ff/1#product-JKL" ,
103
133
"versions" : [
104
134
{
105
- "range" : " vers:semver />=1.0|<=4.4" ,
135
+ "range" : " vers:generic />=1.0|<=4.4" ,
106
136
"status" : " unaffected"
137
+ }
138
+ ]
139
+ }
140
+ ]
141
+ },
142
+ {
143
+ "id" : " CVE-2021-44228" ,
144
+ "source" : {
145
+ "name" : " NVD" ,
146
+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2021-44228"
147
+ },
148
+ "ratings" : [
149
+ {
150
+ "source" : {
151
+ "name" : " NVD" ,
152
+ "url" : " https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/CR:X/IR:X/AR:X/MAV:X/MAC:X/MPR:X/MUI:X/MS:X/MC:N/MI:N/MA:N&version=3.1"
153
+ },
154
+ "score" : 0.0 ,
155
+ "severity" : " none" ,
156
+ "method" : " CVSSv31" ,
157
+ "vector" : " AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/CR:X/IR:X/AR:X/MAV:X/MAC:X/MPR:X/MUI:X/MS:X/MC:N/MI:N/MA:N"
158
+ }
159
+ ],
160
+ "analysis" : {
161
+ "state" : " resolved" ,
162
+ "detail" : " This version of Product JKL has been fixed."
163
+ },
164
+ "affects" : [
165
+ {
166
+ "ref" : " urn:cdx:e4c3eedc-4978-470c-ad02-6ffff63738ff/1#product-JKL" ,
167
+ "versions" : [
168
+ {
169
+ "version" : " 5.1"
107
170
},
108
171
{
109
- "version" : " 5.1" ,
110
- "status" : " unaffected"
172
+ "version" : " 5.2"
111
173
}
112
174
]
113
175
}
149
211
"status" : " affected"
150
212
},
151
213
{
152
- "range" : " vers:semver />=2.9|<=4.1" ,
214
+ "range" : " vers:generic />=2.9|<=4.1" ,
153
215
"status" : " affected"
154
216
}
155
217
]
158
220
"ref" : " urn:cdx:e4c3eedc-4978-470c-ad02-6ffff63738ff/1#product-JKL" ,
159
221
"versions" : [
160
222
{
161
- "range" : " vers:semver />=4.5|<=5.0" ,
223
+ "range" : " vers:generic />=4.5|<=5.0" ,
162
224
"status" : " affected"
163
225
},
164
226
{
188
250
}
189
251
],
190
252
"analysis" : {
191
- "state" : " not_affected"
253
+ "state" : " not_affected" ,
254
+ "justification" : " code_not_present" ,
255
+ "response" : [" will_not_fix" ],
256
+ "detail" : " These versions of Product ABC are not affected by the vulnerability. Class with vulnerable code was removed before shipping."
192
257
},
193
258
"affects" : [
194
259
{
195
260
"ref" : " urn:cdx:cbb2cd68-2857-43b8-a10b-e8c03d277d18/1#product-ABC" ,
196
261
"versions" : [
197
262
{
198
- "range" : " vers:semver />=1.0|<=2.3" ,
263
+ "range" : " vers:generic />=1.0|<=2.3" ,
199
264
"status" : " unaffected"
200
265
},
201
266
{
202
267
"version" : " 2.5" ,
203
268
"status" : " unaffected"
204
269
},
205
270
{
206
- "range" : " vers:semver />=2.7|<=2.8" ,
271
+ "range" : " vers:generic />=2.7|<=2.8" ,
207
272
"status" : " unaffected"
208
273
},
209
274
{
216
281
"ref" : " urn:cdx:e4c3eedc-4978-470c-ad02-6ffff63738ff/1#product-JKL" ,
217
282
"versions" : [
218
283
{
219
- "range" : " vers:semver />=1.0|<=4.4" ,
284
+ "range" : " vers:generic />=1.0|<=4.4" ,
220
285
"status" : " unaffected"
221
286
},
222
287
{
226
291
]
227
292
}
228
293
]
294
+ },
295
+ {
296
+ "id" : " CVE-2021-45105" ,
297
+ "source" : {
298
+ "name" : " NVD" ,
299
+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2021-45105"
300
+ },
301
+ "ratings" : [
302
+ {
303
+ "source" : {
304
+ "name" : " NVD" ,
305
+ "url" : " https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/CR:X/IR:X/AR:X/MAV:X/MAC:X/MPR:X/MUI:X/MS:X/MC:N/MI:N/MA:N&version=3.1"
306
+ },
307
+ "score" : 0.0 ,
308
+ "severity" : " none" ,
309
+ "method" : " CVSSv31" ,
310
+ "vector" : " AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/CR:X/IR:X/AR:X/MAV:X/MAC:X/MPR:X/MUI:X/MS:X/MC:N/MI:N/MA:N"
311
+ }
312
+ ],
313
+ "analysis" : {
314
+ "state" : " not_affected" ,
315
+ "justification" : " code_not_present" ,
316
+ "response" : [" will_not_fix" ],
317
+ "detail" : " These versions of Product JKL are not affected by the vulnerability. Log4j was not included in those versions at all."
318
+ },
319
+ "affects" : [
320
+ {
321
+ "ref" : " urn:cdx:e4c3eedc-4978-470c-ad02-6ffff63738ff/1#product-JKL" ,
322
+ "versions" : [
323
+ {
324
+ "range" : " vers:generic/>=1.0|<=4.4" ,
325
+ "status" : " unaffected"
326
+ }
327
+ ]
328
+ }
329
+ ]
330
+ },
331
+ {
332
+ "id" : " CVE-2021-45105" ,
333
+ "source" : {
334
+ "name" : " NVD" ,
335
+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2021-45105"
336
+ },
337
+ "ratings" : [
338
+ {
339
+ "source" : {
340
+ "name" : " NVD" ,
341
+ "url" : " https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/CR:X/IR:X/AR:X/MAV:X/MAC:X/MPR:X/MUI:X/MS:X/MC:N/MI:N/MA:N&version=3.1"
342
+ },
343
+ "score" : 0.0 ,
344
+ "severity" : " none" ,
345
+ "method" : " CVSSv31" ,
346
+ "vector" : " AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/CR:X/IR:X/AR:X/MAV:X/MAC:X/MPR:X/MUI:X/MS:X/MC:N/MI:N/MA:N"
347
+ }
348
+ ],
349
+ "analysis" : {
350
+ "state" : " resolved" ,
351
+ "detail" : " This version of Product JKL has been fixed."
352
+ },
353
+ "affects" : [
354
+ {
355
+ "ref" : " urn:cdx:e4c3eedc-4978-470c-ad02-6ffff63738ff/1#product-JKL" ,
356
+ "versions" : [
357
+ {
358
+ "version" : " 5.2"
359
+ }
360
+ ]
361
+ }
362
+ ]
229
363
}
230
364
]
231
365
}
0 commit comments