Improper Verification of Cryptographic Signature in Spring Boot - CVE-2024-38807
Published: August 23, 2024
Vulnerability identifier: #VU96484
CSH Severity: Low
CVSS v4: 7.2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-38807
CWE-ID: CWE-347
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to incorrect signature verification when using spring-boot-loader and spring-boot-loader-classic for nested jar files. A local user can forge the signature to spoof identity of the code signer.
Affected software
Spring Boot
Communications Service Catalog and Design
Oracle Communications Cloud Native Core Console
Library Support for Spring
Communications Service Catalog and Design
Oracle Communications Cloud Native Core Console
Library Support for Spring
How to mitigate CVE-2024-38807
Install updates from vendor's website.
Spring Boot - addressed in versions 2.7.22, 3.0.17, 3.1.13, 3.2.9, 3.3.3
Library Support for Spring - update to 2.7.29
Library Support for Spring - update to 2.7.29