CVE-2024-22949 describes a potential NullPointerException in JFreeChart v1.5.4, specifically within the /chart/annotations/CategoryLineAnnotation component, affecting the jfree jfreechart product. It carries a critical CVSS score of 9.1, indicating a network-exploitable vulnerability with low attack complexity and high impact on confidentiality and availability. However, the existence of this vulnerability is disputed by multiple third parties, suggesting the initial submission may have been based on unreliable tooling. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.4CPE matchmatch criteria | cpe:2.3:a:jfree:jfreechart:1.5.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.