Vulnerabilities > CVE-2024-23081 - NULL Pointer Dereference vulnerability in Threeten Backport 1.6.8

047910
CVSS 3.3 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
LOW
local
low complexity
threeten
CWE-476

Summary

ThreeTen Backport v1.6.8 was discovered to contain a NullPointerException via the component org.threeten.bp.LocalDate::compareTo(ChronoLocalDate). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

Vulnerable Configurations

Part Description Count
Application
Threeten
1

Common Weakness Enumeration (CWE)