CVE-2024-38807

Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another.
Configurations

No configuration.

History

27 Mar 2025, 17:15

Type Values Removed Values Added
CWE CWE-347
CWE-290

17 Jan 2025, 20:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250117-0006/ -

Information

Published : 2024-08-23 09:15

Updated : 2025-03-27 17:15


NVD link : CVE-2024-38807

Mitre link : CVE-2024-38807

CVE.ORG link : CVE-2024-38807


JSON object : View

Products Affected

No product.

CWE
CWE-290

Authentication Bypass by Spoofing

CWE-347

Improper Verification of Cryptographic Signature