CVE-2024-23080 (Medium) detected in joda-time-2.12.2.jar #4249
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
security fix
Security fix generated by WhiteSource
triaged
Issues labeled as 'Triaged' have been reviewed and are deemed actionable.
CVE-2024-23080 - Medium Severity Vulnerability
Vulnerable Library - joda-time-2.12.2.jar
Date and time library to replace JDK date handling
Library home page: https://www.joda.org/joda-time/
Path to dependency file: /build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/joda-time/joda-time/2.12.2/78e18a7b4180e911dafba0a412adfa82c1e3d14b/joda-time-2.12.2.jar
Dependency Hierarchy:
Found in HEAD commit: 90fe3bb65dda815bbcf9b9ce87c1044f631d8a8b
Found in base branch: main
Vulnerability Details
Joda Time v2.12.5 was discovered to contain a NullPointerException via the component org.joda.time.format.PeriodFormat::wordBased(Locale).
Publish Date: 2024-04-10
URL: CVE-2024-23080
CVSS 3 Score Details (5.5)
Base Score Metrics:
The text was updated successfully, but these errors were encountered: