Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46296
HistoryApr 10, 2024 - 5:22 a.m.

Integer Overflow

2024-04-1005:22:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
integer overflow
threeten backport
missing validation
datetimeformatter
stringindexoutofboundsexception

AI Score

7

Confidence

High

EPSS

0

Percentile

15.5%

ThreeTen backport is vulnerable to integer overflow. The vulnerability is due to missing string validation in the org.threeten.bp.format.DateTimeFormatter::parse(CharSequence, ParsePosition) method, which returns a StringIndexOutOfBoundsException if the CharSequence is empty.

AI Score

7

Confidence

High

EPSS

0

Percentile

15.5%