CVE-2024-41107 is a critical vulnerability in Apache CloudStack's SAML authentication mechanism (disabled by default) affecting versions 4.5.0 through 4.18.2.1 and 4.19.0.0 through 4.19.0.2. The vulnerability arises from the failure to enforce signature checks on SAML responses. An attacker can exploit this by submitting a spoofed, unsigned SAML response with a known or guessed username and other user details, thereby bypassing authentication and gaining unauthorized access to resources owned or accessible by SAML-enabled user accounts.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (PoC) exploit for CVE-2024-41107, a critical authentication bypass vulnerability in Apache CloudStack's SAML authentication mechanism. The repository consists of two files: 'PoC.py', a Python script implementing the exploit, and 'README.md', which provides background, usage instructions, and mitigation advice. The exploit works by generating unsigned SAML responses for a list of usernames and submitting them to the CloudStack API endpoint. If the target is vulnerable, the script can obtain valid session IDs, granting unauthorized access to user accounts. The code is straightforward, using Python's requests and BeautifulSoup libraries to interact with the API and parse responses. The main fingerprintable endpoint is the CloudStack API URL, which must be set to the target instance. The exploit demonstrates the vulnerability but does not include weaponized or post-exploitation payloads, classifying it as a PoC.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.