VDB
CISA-2024-38807
CISA-2024-38807
PUBLISHED
CVSS 6.3 MEDIUM
Reported by vmware · Published August 23, 2024
Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another.
Risk Scores
CVSS 3.1
6.3
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Spring | Spring Boot | 2.7.x, 3.0.x, 3.1.x |
| Spring | Spring Boot | 3.0.x, 3.1.x, 3.2.x |
Timeline
- Aug 23, 2024 CVE Published
- Mar 27, 2025 CVE Updated