Apfloat · Apfloat · CVE-2024-23085
**Name of the Vulnerable Software and Affected Versions**
Apfloat version 1.10.1
**Description**
A NullPointerException was discovered in Apfloat via the component `org.apfloat.internal.DoubleScramble::scramble(double[], int, int[])`. However, the existence of this issue is disputed by multiple third parties due to potentially insufficient evidence.
**Recommendations**
For Apfloat version 1.10.1, consider temporarily disabling the `scramble` function in `org.apfloat.internal.DoubleScramble` as a mitigation measure until further clarification or a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.