Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreApplications that use spring-boot-loader
or spring-boot-loader-classic
and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another.
Spring Boot
Users of affected versions should upgrade to the corresponding fixed version.
Affected version(s) | Fix version | Availability |
---|---|---|
2.7.x | 2.7.22 | Enterprise Support Only |
3.0.x | 3.0.17 | Enterprise Support Only |
3.1.x | 3.1.13 | Enterprise Support Only |
3.2.x | 3.2.9 | OSS |
3.3.x | 3.3.3 | OSS |
The issue was identified and responsibly reported by Yufan You.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy