Apache Flink 1.11.2, vulnerable to CVE-2020-17519: the JobManager REST handler for /jobmanager/logs/<name> double-decodes the file name, so ..%252f sequences walk out of the log directory and read any file the process can read.
Not startedDockercommit 3dc6301x86_64 · aarch64Secret
Exploit CVE-2020-17519 to read files outside the Flink log directory and read the flag.
The brief for this lab lives in its repository.