First published: Wed Apr 10 2024(Updated: )
Joda Time v2.12.5 was discovered to contain a NullPointerException via the component org.joda.time.format.PeriodFormat::wordBased(Locale). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joda-Time |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-23080 is currently disputed and lacks sufficient evidence to confirm a significant impact.
As of now, there are no specific patches or fixes available for CVE-2024-23080 due to the ongoing debate about its validity.
CVE-2024-23080 affects the component org.joda.time.format.PeriodFormat::wordBased(Locale) in Joda Time v2.12.5.
Joda Time v2.12.5 is reported to be vulnerable to CVE-2024-23080.
Multiple third parties dispute the existence of CVE-2024-23080, stating there is insufficient evidence to confirm it as a vulnerability.