Apache CouchDB 2.1.0, vulnerable to CVE-2017-12635: the validation function (JavaScript) reads the last roles key of a _users document while Erlang stores the first, so an anonymous signup with two roles keys becomes a server admin.
Not startedDockercommit 32e75ecx86_64 · aarch64Secret
Exploit CVE-2017-12635 to make yourself a CouchDB admin and read the flag.
The brief for this lab lives in its repository.