Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 27 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-290 CWE-347  | 
Fri, 17 Jan 2025 20:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Fri, 23 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Fri, 23 Aug 2024 08:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another. | |
| Title | CVE-2024-38807: Signature Forgery Vulnerability in Spring Boot's Loader | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: vmware
Published: 2024-08-23T08:26:11.826Z
Updated: 2025-03-27T16:36:21.258Z
Reserved: 2024-06-19T22:31:57.186Z
Link: CVE-2024-38807
Updated: 2025-01-17T20:02:54.673Z
Status : Awaiting Analysis
Published: 2024-08-23T09:15:07.453
Modified: 2025-03-27T17:15:56.383
Link: CVE-2024-38807
No data.