Improper Verification of Cryptographic Signature in Spring Boot - CVE-2024-38807

 

Improper Verification of Cryptographic Signature in Spring Boot - CVE-2024-38807

Published: August 23, 2024


Vulnerability identifier: #VU96484
CSH Severity: Low
CVSS v4: 7.2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-38807
CWE-ID: CWE-347
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass implemented security restrictions.

The vulnerability exists due to incorrect signature verification when using spring-boot-loader and spring-boot-loader-classic for nested jar files. A local user can forge the signature to spoof identity of the code signer.


Affected software

Spring Boot
Communications Service Catalog and Design
Oracle Communications Cloud Native Core Console
Library Support for Spring

How to mitigate CVE-2024-38807

Install updates from vendor's website.

Spring Boot - addressed in versions 2.7.22, 3.0.17, 3.1.13, 3.2.9, 3.3.3
Library Support for Spring - update to 2.7.29

External References

Related Security Bulletins