{"@context":"https://spdx.org/rdf/3.0.1/spdx-context.jsonld","@graph":[{"type":"CreationInfo","@id":"_:CreationInfo0","created":"2011-04-05T23:00:00Z","createdBy":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded"],"createdUsing":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0"],"specVersion":"3.0.1"},{"type":"CreationInfo","@id":"_:CreationInfo1","created":"2025-10-10T02:38:31Z","createdBy":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded"],"createdUsing":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0"],"specVersion":"3.0.1"},{"type":"Organization","spdxId":"http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias"}],"name":"OpenEmbedded"},{"type":"Tool","spdxId":"http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias"}],"name":"oe-spdx-creator 1.0"},{"type":"SpdxDocument","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/document/package-openssh-sftp","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/doc/openssh/package-openssh-sftp/openssh/UNIHASH/document/package-openssh-sftp"}],"name":"package-openssh-sftp","profileConformance":["build","core","security","simpleLicensing","software"],"rootElement":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-sftp"]},{"type":"software_Package","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-sftp","creationInfo":"_:CreationInfo1","description":"Secure rlogin/rsh/rcp/telnet replacement (OpenSSH) Ssh (Secure Shell) is a program for logging into a remote machine and for executing commands on a remote machine.","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/7e9e56492683c116c29a12da2d28ebd9df4798b3e01de0ffdc0e862733426fab/openssh/UNIHASH/package/openssh-sftp"}],"externalIdentifier":[{"type":"ExternalIdentifier","externalIdentifierType":"cpe23","identifier":"cpe:2.3:*:*:openssh:10.2p1:*:*:*:*:*:*:*"}],"name":"openssh-sftp","summary":"A suite of security-related network utilities based on the SSH protocol including the ssh client and sshd server","software_primaryPurpose":"install","software_homePage":"http://www.openssh.com/","software_packageVersion":"10.2p1"},{"type":"software_File","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-sftp/file/1","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/7e9e56492683c116c29a12da2d28ebd9df4798b3e01de0ffdc0e862733426fab/openssh/UNIHASH/package/openssh-sftp/file/1"}],"name":"usr/bin/sftp","verifiedUsing":[{"type":"Hash","algorithm":"sha256","hashValue":"de48274dd95bab52a08fcbc89241de69b266c3ed75b84973a1c0bc5eaa28da00"}]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/relationship/852325d33ba683191688ed52e973a0f2","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/7e9e56492683c116c29a12da2d28ebd9df4798b3e01de0ffdc0e862733426fab/openssh/UNIHASH/relationship/852325d33ba683191688ed52e973a0f2"}],"from":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-sftp","relationshipType":"hasDeclaredLicense","to":["http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/license/3_27_0/BSD-2-Clause_AND_BSD-3-Clause_AND_ISC_AND_MIT"]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/relationship/a1b9609ac402e8eb03fc0cbc513e833c","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/7e9e56492683c116c29a12da2d28ebd9df4798b3e01de0ffdc0e862733426fab/openssh/UNIHASH/relationship/a1b9609ac402e8eb03fc0cbc513e833c"}],"from":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-sftp","relationshipType":"hasAssociatedVulnerability","to":["http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2007-2768","http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2008-3844","http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2014-9278","http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2023-51767"]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/relationship/acccf74864a67f05fccf017dfc6467dd","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/7e9e56492683c116c29a12da2d28ebd9df4798b3e01de0ffdc0e862733426fab/openssh/UNIHASH/relationship/acccf74864a67f05fccf017dfc6467dd"}],"from":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-sftp","relationshipType":"contains","to":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-sftp/file/1"]},{"type":"LifecycleScopedRelationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/relationship/b5a9cc4771adbc1943014079e0d0c18d","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/7e9e56492683c116c29a12da2d28ebd9df4798b3e01de0ffdc0e862733426fab/openssh/UNIHASH/relationship/b5a9cc4771adbc1943014079e0d0c18d"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/build/recipe","relationshipType":"hasOutput","to":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-sftp"],"scope":"build"},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/vex-not-affected/2b41fae423a70ead3fa8ea90448c3c21","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/7e9e56492683c116c29a12da2d28ebd9df4798b3e01de0ffdc0e862733426fab/openssh/UNIHASH/vex-not-affected/2b41fae423a70ead3fa8ea90448c3c21"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2007-2768","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-sftp"],"security_vexVersion":"1.0.0","security_impactStatement":"This CVE is specific to OpenSSH with the pam opie which we don't build/use here.","security_justificationType":"vulnerableCodeNotPresent"},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/vex-not-affected/93aebea791545446f806e6ed2870264f","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/7e9e56492683c116c29a12da2d28ebd9df4798b3e01de0ffdc0e862733426fab/openssh/UNIHASH/vex-not-affected/93aebea791545446f806e6ed2870264f"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2023-51767","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-sftp"],"security_vexVersion":"1.0.0","security_impactStatement":"It was demonstrated on modified sshd and does not exist in upstream openssh https://bugzilla.mindrot.org/show_bug.cgi?id=3656#c1."},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/vex-not-affected/abbfddbf92fa010463f9946c63bbdf67","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/7e9e56492683c116c29a12da2d28ebd9df4798b3e01de0ffdc0e862733426fab/openssh/UNIHASH/vex-not-affected/abbfddbf92fa010463f9946c63bbdf67"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2014-9278","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-sftp"],"security_vexVersion":"1.0.0","security_impactStatement":"This CVE is specific to OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when running in a Kerberos environment","security_justificationType":"vulnerableCodeNotPresent"},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/vex-not-affected/ceb9a7279219a50ccb3a49e941e2f7e8","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/7e9e56492683c116c29a12da2d28ebd9df4798b3e01de0ffdc0e862733426fab/openssh/UNIHASH/vex-not-affected/ceb9a7279219a50ccb3a49e941e2f7e8"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8c370fd04af5f1e4936bd291fc89feb1fc07b6e4e66866b5a606cebad1858dca/openssh/UNIHASH/vulnerability/CVE-2008-3844","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/openssh-b3654395-a76e-53f0-8712-cc47496f463e/cd92560be14c59b4cd3b85b4e68d2f35ac203d50767c6577c68ff32563e4bdd4/package/openssh-sftp"],"security_vexVersion":"1.0.0","security_impactStatement":"Only applies to some distributed RHEL binaries.","security_justificationType":"vulnerableCodeNotPresent"}]}