VDB

CISA-2024-38807

CISA-2024-38807 PUBLISHED CVSS 6.3 MEDIUM

Reported by vmware · Published August 23, 2024

Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another.

Risk Scores

CVSS 3.1
6.3
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
SpringSpring Boot2.7.x, 3.0.x, 3.1.x
SpringSpring Boot3.0.x, 3.1.x, 3.2.x

Timeline

  • Aug 23, 2024 CVE Published
  • Mar 27, 2025 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›