No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2526 | Signature forgery in Spring Boot's Loader |
Github GHSA |
GHSA-7cj3-x93g-gj76 | Signature forgery in Spring Boot's Loader |
Thu, 27 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-290 CWE-347 |
Fri, 17 Jan 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 23 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 23 Aug 2024 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another. | |
| Title | CVE-2024-38807: Signature Forgery Vulnerability in Spring Boot's Loader | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2025-03-27T16:36:21.258Z
Reserved: 2024-06-19T22:31:57.186Z
Link: CVE-2024-38807
Updated: 2025-01-17T20:02:54.673Z
Status : Awaiting Analysis
Published: 2024-08-23T09:15:07.453
Modified: 2025-03-27T17:15:56.383
Link: CVE-2024-38807
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA