CVE-2024-38807
Spring Boot Loader: signature forgery in nested jar verification
Technology
Spring Boot
CVSS Score
6.3 / 10.0
Affected Versions
3.3.0 to 3.3.2; 3.2.0 to 3.2.8; 3.1.0 to 3.1.12; 3.0.0 to 3.0.16; 2.7.0 to 2.7.21
Upstream Fix
3.3.3, 3.2.9 (public); 3.1.13, 3.0.17, 2.7.22 (Enterprise Support Only)
Published
August 23, 2024
OSSeva Coverage
Fixed upstream
Description
Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that verifies the signatures of nested jar files may accept content that appears to have been signed by one signer when it was in fact signed by another. Applications without such custom verification code are not affected. CVSS is VMware's score as the CNA.
Is your Spring Boot deployment affected?
If you're running 3.3.0 to 3.3.2; 3.2.0 to 3.2.8; 3.1.0 to 3.1.12; 3.0.0 to 3.0.16; 2.7.0 to 2.7.21, you need this patch. Book a discovery call to get covered.