CVE-2024-23081: Threeten Backport
Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.
ThreeTen Backport v1.6.8 was discovered to contain a NullPointerException via the component org.threeten.bp.LocalDate::compareTo(ChronoLocalDate). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.
Affected products
- Threeten Threeten Backport: version 1.6.8 only
Published 2024-04-08. Last modified 2026-07-09.