Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-23078

Опубликовано: 08 апр. 2024
Источник: redhat
CVSS3: 5.5

Описание

JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

A flaw was found in the JGraphT Core. The affected version of this package contains a Null Pointer Exception via the org.jgrapht.alg.util.ToleranceDoubleComparator::compare component.

Отчет

The Null Pointer Exception in the ToleranceDoubleComparator::compare method of the JGraphT Core library is classified as a moderate severity issue due to its potential to disrupt application stability under certain conditions. This flaw can cause runtime exceptions when null values are encountered during the comparison process, leading to abrupt termination of algorithms that rely on this comparator. While it does not pose a security risk or lead to data corruption, it affects the reliability and robustness of graph-related operations, especially in environments where null inputs might be prevalent.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 6jgrapht-coreNot affected
Migration Toolkit for Runtimesjgrapht-coreNot affected
Red Hat Process Automation 7jgrapht-coreWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-395
https://bugzilla.redhat.com/show_bug.cgi?id=2274095jgrapht-core: Null Pointer Exception

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
почти 2 года назад

JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

CVSS3: 9.1
nvd
почти 2 года назад

JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

CVSS3: 9.1
github
почти 2 года назад

JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double).

5.5 Medium

CVSS3