← back
CVE-2024-38807mediumCWE-290CWE-347

CVE-2024-38807: Signature Forgery Vulnerability in Spring Boot's Loader

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.3epss 0.1%
exploitation probability
0.1%top 98% of all CVEs
observed exploitation
nono source reports it
Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected products
Spring · Spring Boot