Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2024-38807

Spring Boot Loader: signature forgery in nested jar verification

Technology

Spring Boot

CVSS Score

6.3 / 10.0

Affected Versions

3.3.0 to 3.3.2; 3.2.0 to 3.2.8; 3.1.0 to 3.1.12; 3.0.0 to 3.0.16; 2.7.0 to 2.7.21

Upstream Fix

3.3.3, 3.2.9 (public); 3.1.13, 3.0.17, 2.7.22 (Enterprise Support Only)

Published

August 23, 2024

OSSeva Coverage

Fixed upstream

Description

Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that verifies the signatures of nested jar files may accept content that appears to have been signed by one signer when it was in fact signed by another. Applications without such custom verification code are not affected. CVSS is VMware's score as the CNA.

Upstream record: NVD · CVE.org

Is your Spring Boot deployment affected?

If you're running 3.3.0 to 3.3.2; 3.2.0 to 3.2.8; 3.1.0 to 3.1.12; 3.0.0 to 3.0.16; 2.7.0 to 2.7.21, you need this patch. Book a discovery call to get covered.