VYPR
High severity8.1NVD Advisory· Published Jul 19, 2024· Updated Jun 17, 2026

CVE-2024-41107

CVE-2024-41107

Description

The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments where SAML authentication is enabled, an attacker that initiates CloudStack SAML single sign-on authentication can bypass SAML authentication by submitting a spoofed SAML response with no signature and known or guessed username and other user details of a SAML-enabled CloudStack user-account. In such environments, this can result in a complete compromise of the resources owned and/or accessible by a SAML enabled user-account.

Affected users are recommended to disable the SAML authentication plugin by setting the "saml2.enabled" global setting to "false", or upgrade to version 4.18.2.2, 4.19.1.0 or later, which addresses this issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Apache/Cloudstack3 versions
    cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*range: >=4.5.0,<4.18.2.2
    • (no CPE)range: before 4.18.2.2, 4.19.1.0
    • (no CPE)range: 4.5.0

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.