CVE-2024-23080: Joda Time
Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.
Joda Time v2.12.5 was discovered to contain a NullPointerException via the component org.joda.time.format.PeriodFormat::wordBased(Locale). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.
Affected products
- Joda Joda Time: version 2.12.5 only
Published 2024-04-10. Last modified 2026-07-09.