« Volver al listado

CVE-2024-38807

Estado: AplazadaMedia (6.3)—

Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-38807",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-38807",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-23T17:13:03.601236Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@vmware.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.3,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "Spring",
          "product": "Spring Boot",
          "versions": [
            {
              "status": "affected",
              "version": "2.7.x",
              "lessThan": "2.7.22",
              "versionType": "enterprise support only"
            },
            {
              "status": "affected",
              "version": "3.0.x",
              "lessThan": "3.0.17",
              "versionType": "enterprise support only"
            },
            {
              "status": "affected",
              "version": "3.1.x",
              "lessThan": "3.1.13",
              "versionType": "enterprise support only"
            },
            {
              "status": "affected",
              "version": "3.2.x",
              "lessThan": "3.2.9",
              "versionType": "OSS"
            },
            {
              "status": "affected",
              "version": "3.3.x",
              "lessThan": "3.3.3",
              "versionType": "OSS"
            }
          ],
          "packageName": "Spring Boot",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-08-23T09:15:07.453",
  "references": [
    {
      "url": "https://spring.io/security/cve-2024-38807",
      "source": "security@vmware.com"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20250117-0006/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-290"
        },
        {
          "lang": "en",
          "value": "CWE-347"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another."
    },
    {
      "lang": "es",
      "value": "Las aplicaciones que utilizan spring-boot-loader o spring-boot-loader-classic y contienen código personalizado que realiza la verificación de firmas de archivos jar anidados pueden ser vulnerables a la falsificación de firmas cuando el contenido que parece haber sido firmado por un firmante, de hecho, sido firmado por otro."
    }
  ],
  "lastModified": "2026-06-17T07:41:05.037",
  "sourceIdentifier": "security@vmware.com"
}