---
id: CVE-2023-52070
title: >-
  JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via
  the 'setSeriesNeedle(int index, int type)' method
summary: >-
  JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via
  the 'setSeriesNeedle(int index, int type)' method. NOTE: this is disputed by
  multiple third parties who believe there was not reasonable evidence to
  determine…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-125
vendor: jfree
product: jfreechart
affected:
  - jfreechart = 1.5.4
published: '2024-04-10'
updated: '2026-07-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-52070'
references:
  - url: 'https://gist.github.com/LLM4IG/f55de46e65fb5a19b7815adb36fd858b'
    label: cve@mitre.org
  - url: 'http://jfreechart.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://jfreeorg.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://gist.github.com/LLM4IG/f55de46e65fb5a19b7815adb36fd858b'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00227
epssPercentile: 0.13711
ingestedAt: '2026-07-04T20:57:37.128Z'
---

## Overview

JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)' method. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

## Affected

- `jfreechart = 1.5.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
