CVE-2024-23080: Null Pointer Dereference
Joda Time v2.12.5 was discovered to contain a NullPointerException via the component org.joda.time.format.PeriodFormat::wordBased(Locale). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.
Other sources
Joda.org Joda-Time is vulnerable to a denial of service, caused by a NullPointerException flaw in the org.joda.time.format.PeriodFormat::wordBased(Locale) compoent. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23080?
The severity of CVE-2024-23080 is currently disputed and lacks sufficient evidence to confirm a significant impact.
How can I fix CVE-2024-23080?
As of now, there are no specific patches or fixes available for CVE-2024-23080 due to the ongoing debate about its validity.
What component is affected by CVE-2024-23080?
CVE-2024-23080 affects the component org.joda.time.format.PeriodFormat::wordBased(Locale) in Joda Time v2.12.5.
Which version of Joda Time is vulnerable to CVE-2024-23080?
Joda Time v2.12.5 is reported to be vulnerable to CVE-2024-23080.
Is there any consensus about the existence of CVE-2024-23080?
Multiple third parties dispute the existence of CVE-2024-23080, stating there is insufficient evidence to confirm it as a vulnerability.