CVE-2023-52070

JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)' method. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jfree:jfreechart:1.5.4:*:*:*:*:*:*:*

History

27 May 2025, 14:20

Type Values Removed Values Added
First Time Jfree jfreechart
Jfree
CPE cpe:2.3:a:jfree:jfreechart:1.5.4:*:*:*:*:*:*:*
References () http://jfreechart.com - () http://jfreechart.com - Broken Link
References () http://jfreeorg.com - () http://jfreeorg.com - Broken Link
References () https://gist.github.com/LLM4IG/f55de46e65fb5a19b7815adb36fd858b - () https://gist.github.com/LLM4IG/f55de46e65fb5a19b7815adb36fd858b - Third Party Advisory

21 Nov 2024, 08:39

Type Values Removed Values Added
References () http://jfreechart.com - () http://jfreechart.com -
References () http://jfreeorg.com - () http://jfreeorg.com -
References () https://gist.github.com/LLM4IG/f55de46e65fb5a19b7815adb36fd858b - () https://gist.github.com/LLM4IG/f55de46e65fb5a19b7815adb36fd858b -

16 Aug 2024, 15:35

Type Values Removed Values Added
CWE CWE-125
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.4

14 May 2024, 14:20

Type Values Removed Values Added
Summary
  • (es) Se descubrió que JFreeChart v1.5.4 era vulnerable a ArrayIndexOutOfBounds mediante el método 'setSeriesNeedle(int index, int type)'. NOTA: esto es cuestionado por varios terceros que creen que no había pruebas razonables para determinar la existencia de una vulnerabilidad. Es posible que la presentación se haya basado en una herramienta que no es lo suficientemente sólida para la identificación de vulnerabilidades.

11 Apr 2024, 19:15

Type Values Removed Values Added
Summary (en) JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)' method. (en) JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)' method. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

10 Apr 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-10 19:15

Updated : 2025-05-27 14:20


NVD link : CVE-2023-52070

Mitre link : CVE-2023-52070

CVE.ORG link : CVE-2023-52070


JSON object : View

Products Affected

jfree

  • jfreechart
CWE
CWE-125

Out-of-bounds Read