Graylog contains an authenticated arbitrary class loading and instantiation flaw in its cluster configuration mechanism. In affected versions starting from 2.0.0 and before 5.1.11 and 5.2.4, a HTTP PUT request to /api/system/cluster_config/ can supply a fully qualified class name used as a cluster config key. As part of validation, Graylog loads the referenced class through the class loader and can instantiate arbitrary classes that expose a single-argument String constructor. If the requester has the required cluster configuration permissions, attacker-controlled class instantiation occurs during request processing. This can trigger arbitrary code paths executed during object construction. The advisory specifically notes java.io.File as a practical example: interaction with the internal web-server stack can cause the contents of the referenced file to be included in the REST response, resulting in information disclosure.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
java.io.File case can return entire file contents in the API response. The vulnerability therefore impacts confidentiality and potentially integrity and availability, depending on what constructor side effects can be triggered in the deployed environment.If you can’t patch tonight, do this now.
clusterconfigentry:create and clusterconfigentry:edit. Reduce exposure of the Graylog API to trusted management networks only, enforce least privilege for roles that can modify cluster configuration, and monitor for suspicious authenticated PUT requests to /api/system/cluster_config/. Review logs for unexpected use of fully qualified class names in cluster configuration operations and rotate credentials for privileged Graylog accounts if compromise is suspected.Patch, then assume compromise.
/api/system/cluster_config/ endpoint no longer permits attacker-controlled arbitrary class loading or instantiation.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone proof-of-concept exploit for CVE-2024-24824 affecting Graylog. It contains two files: a README describing the research context and exploit goals, and a single Python exploit script at exploit/exploit.py. The script is the main entry point and implements an authenticated web exploit chain against Graylog's API. The exploit workflow is: authenticate to the target Graylog server using supplied credentials, obtain a session identifier from /api/system/sessions, query /api/ to retrieve the server version, perform a version-range check to estimate vulnerability, then launch the exploit chain and wait for a reverse shell connection on an attacker-specified host/port. The code includes a reverse-shell handler that binds to 0.0.0.0 on the chosen port and provides interactive command execution once the target connects back. Based on the README and visible code, the exploit targets authenticated arbitrary class loading/deserialization abuse in Graylog and focuses specifically on achieving remote code execution rather than merely demonstrating class instantiation. The repository is not part of a larger exploit framework. It is operational rather than just a detection script because it includes exploitation logic and a shell-handling payload path. Fingerprintable artifacts include Graylog API paths, Graylog-specific headers, the authentication cookie name, and the listener bind address used for the reverse shell.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.