SAML Authentication Vulnerability in CloudStack Environments

CVE-2024-41107
8.1HIGH

Key Information

Vendor
Apache
Status
Apache Cloudstack
Vendor
CVE Published:
19 July 2024

Badges

👾 Exploit Exists🟡 EPSS 72%📰 News Worthy

Summary

CVE-2024-41107 is a SAML authentication vulnerability that affects Apache CloudStack environments. The vulnerability allows attackers to bypass SAML authentication and gain unauthorized access to user accounts and control over cloud resources. It is recommended for affected users to disable the SAML authentication plugin or upgrade to the patched versions 4.18.2.2 or 4.19.1.0. An exploit for this vulnerability has been developed, highlighting the critical nature of the issue. The BSI has issued a security advisory for Apache CloudStack, recommending users to keep their systems up to date and install security updates as soon as they are available. The exploit poses a medium risk for affected systems and can potentially lead to the bypassing of security measures.

Affected Version(s)

Apache CloudStack <= 4.18.2.1

Apache CloudStack <= 4.19.0.2

News Articles

EPSS Score

72% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit exists.

  • Vulnerability published.

  • Vulnerability Reserved.

  • First article discovered by ShapeBlue

Collectors

NVD DatabaseMitre Database6 News Article(s)

Credit

Christian Gross of Netcloud AG
Damon Smith of Apple Services Engineering Security
Adam Pond of Apple Services Engineering Security
Terry Thibault of Apple Services Engineering Security
.