CVE-2021-31602 is an information disclosure vulnerability in Hitachi Vantara Pentaho (through 9.1) and Pentaho Business Intelligence Server (through 7.x). The vulnerability arises from a misconfiguration in the applicationContext security layer, specifically in the applicationContext-spring-security.xml file. The default security configuration allows unauthenticated users to access certain information about the platform without valid credentials, due to insufficient access control enforcement.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small Python proof-of-concept named PWNentaho targeting Pentaho authentication bypass associated with CVE-2021-31602. It contains three files: a minimal README, a plaintext endpoint wordlist, and the main Python script. The core logic is in main.py, which prompts the operator for a target base URL, prepends http:// if no scheme is supplied, creates a local outputs directory, reads endpoint paths from endpoints.txt, and iterates through them with a progress bar. For most endpoints it issues unauthenticated GET requests to target/<endpoint>?require-cfg.js; for endpoints already containing a query string it instead sends POST requests directly to target/<endpoint>. Successful responses are written to per-endpoint text files in outputs/. Timeout and HTTP errors are silently ignored, making the tool suited for bulk probing rather than precise validation. The exploit capability is primarily unauthorized information access and endpoint enumeration rather than code execution or persistence. The endpoint list focuses on Pentaho administrative and informational APIs, including version, authorization, user/role enumeration, scheduler state, repository permissions, session details, mantle admin content, and a datasource management WSDL. Overall, this is an operationally simple web-targeted reconnaissance/exploitation helper for harvesting data from exposed Pentaho endpoints under an authentication bypass condition.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.