CVE-2024-37084 is a vulnerability in Spring Cloud Data Flow versions prior to 2.11.4, where a malicious user with access to the Skipper server API can craft an upload request that writes an arbitrary file to any location on the file system. This flaw allows attackers to compromise the server by writing files outside of intended directories, potentially leading to remote code execution or full system compromise.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository provides a proof-of-concept (PoC) exploit for CVE-2024-37084, a remote code execution vulnerability in VMware Spring Cloud Data Flow. The main file, CVE-2024-37084-Poc.py, is a Python script that automates the creation of a malicious YAML package. This package abuses unsafe deserialization in the target application by referencing a remote Java payload (e.g., a JAR file) in the displayName field using a specially crafted YAML structure. The script zips the malicious package and uploads it to the target's package upload API endpoint (e.g., /api/package/upload). If the target is vulnerable, it will fetch and execute the remote payload, leading to remote code execution (such as a reverse shell). The README.md provides usage instructions, example arguments, and references for payload generation. The exploit requires the attacker to host a malicious payload and have network access to the target's upload endpoint. The repository is structured with a single exploit script and a README, and does not include detection or post-exploitation tooling.
This repository provides a working exploit for CVE-2024-37084, a remote code execution vulnerability. The structure includes a main Python exploit script (cve-2024-37084-exp.py), a helper script to generate a malicious Java payload JAR (generate-yaml-payload.jar.py), and the Java source code for the payload (AwesomeScriptEngineFactory.java). The exploit works by generating a malicious YAML package referencing a remote JAR file containing a Java class that executes arbitrary system commands (such as a reverse shell). The Python script uploads this package to the vulnerable application's /api/package/upload endpoint. The README provides detailed instructions for both detection (using DNSLog) and exploitation (command execution or reverse shell). The exploit is operational and allows for arbitrary command execution on the target. Notable endpoints include the target's upload API, the attacker's payload hosting URL, and DNSLog for detection. The repository is well-structured for both detection and exploitation, with clear separation between payload generation and exploit delivery.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.