CVE-2024-38807 Information
Aug 24, 2024
cve
Description
Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has in fact been signed by another.
Reference
https://spring.io/security/cve-2024-38807
Share on: