Apache Druid 0.20.0, vulnerable to CVE-2021-25646: a crafted ingestion spec re-enables the disabled JavaScript engine through an empty JSON key, so an unauthenticated request runs JavaScript, and therefore commands, on the server.
Not startedDockercommit 28fe54dx86_64 · aarch64Secret
Exploit CVE-2021-25646 to run commands on the Druid server and read /ctf/flag.
The brief for this lab lives in its repository.