Elasticsearch 1.4.2 with dynamic Groovy scripting, vulnerable to CVE-2015-1427: the Groovy sandbox can be escaped through Java reflection, so a script_fields search request runs commands.
Not startedDockercommit f4419afx86_64 · aarch64Secret
Exploit CVE-2015-1427 to run a command on the Elasticsearch server.
The brief for this lab lives in its repository.