StackRadar

CVE-2024-38807

Medium

Advisory

Published 23 Aug 2024In the index since 8 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
1 of 1
affected package

Signature forgery in Spring Boot's Loader

Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
spring-boot-loadermaven2.7.3, 2.7.18, 3.2.0, 3.2.32.7.22, 3.2.99
OSV records
GHSA-7cj3-x93g-gj76

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
mod-agreementsfolio-org0.1.321 of 1See more

mod-agreements folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2024-38807.

Container imageDigestPackageFixed in
folioci/mod-agreements:latest29c3f233a498
spring-boot-loader@2.7.18
2.7.22

Open the chart page →

1,874
mod-licensesfolio-org0.1.321 of 1See more

mod-licenses folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2024-38807.

Container imageDigestPackageFixed in
folioci/mod-licenses:latestcfd6109bf477
spring-boot-loader@2.7.18
2.7.22

Open the chart page →

1,760
mod-oafolio-org0.1.21 of 1See more

mod-oa folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-38807.

Container imageDigestPackageFixed in
folioci/mod-oa:latestae3b069d4ba5
spring-boot-loader@2.7.18
2.7.22

Open the chart page →

1,733
mod-serials-managementfolio-org0.1.11 of 1See more

mod-serials-management folio-org 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-38807.

Container imageDigestPackageFixed in
folioci/mod-serials-management:latest571fa1ffe8c9
spring-boot-loader@2.7.18
2.7.22

Open the chart page →

1,733
mod-service-interactionfolio-org0.1.61 of 1See more

mod-service-interaction folio-org 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-38807.

Container imageDigestPackageFixed in
folioci/mod-service-interaction:latestf53c327a48e8
spring-boot-loader@2.7.18
2.7.22

Open the chart page →

1,733
fstyr-ddp-keycloak-application-platform-configkvalitetsitVerified publisher0.1.131 of 1See more

fstyr-ddp-keycloak-application-platform-config kvalitetsit 0.1.13

1 of the 1 container images this version deploys carry CVE-2024-38807.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
spring-boot-loader@3.2.3
3.2.9

Open the chart page →

3,104
keycloak-application-platform-configkvalitetsitVerified publisher0.0.291 of 1See more

keycloak-application-platform-config kvalitetsit 0.0.29

1 of the 1 container images this version deploys carry CVE-2024-38807.

Container imageDigestPackageFixed in
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
spring-boot-loader@3.2.3
3.2.9

Open the chart page →

3,334
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2024-38807.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
spring-boot-loader@2.7.3
2.7.22

Open the chart page →

5,856
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2024-38807.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
spring-boot-loader@3.2.0
3.2.9

Open the chart page →

11,577

Container images carrying it

9 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
spring-boot-loader@3.2.3
3.2.9
1
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
spring-boot-loader@3.2.3
3.2.9
1
folioci/mod-agreements:latest29c3f233a498
spring-boot-loader@2.7.18
2.7.22
1
folioci/mod-licenses:latestcfd6109bf477
spring-boot-loader@2.7.18
2.7.22
1
folioci/mod-oa:latestae3b069d4ba5
spring-boot-loader@2.7.18
2.7.22
1
folioci/mod-serials-management:latest571fa1ffe8c9
spring-boot-loader@2.7.18
2.7.22
1
folioci/mod-service-interaction:latestf53c327a48e8
spring-boot-loader@2.7.18
2.7.22
1
jhipster/jhipster-registry:latest7184525acd4d
spring-boot-loader@2.7.3
2.7.22
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
spring-boot-loader@3.2.0
3.2.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.