Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://spring.io/security/cve-2024-38807 |
History
Fri, 23 Aug 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 23 Aug 2024 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another. | |
Title | CVE-2024-38807: Signature Forgery Vulnerability in Spring Boot's Loader | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: vmware
Published: 2024-08-23T08:26:11.826Z
Updated: 2024-08-23T17:13:13.853Z
Reserved: 2024-06-19T22:31:57.186Z
Link: CVE-2024-38807
Vulnrichment
Updated: 2024-08-23T17:13:08.901Z
NVD
Status : Awaiting Analysis
Published: 2024-08-23T09:15:07.453
Modified: 2024-08-23T16:18:28.547
Link: CVE-2024-38807
Redhat
No data.