Oracle GlassFish Server Open Source Edition 4.1, vulnerable to CVE-2017-1000028: the admin console on port 4848 decodes the overlong UTF-8 sequence %c0%ae as a dot under /theme/META-INF/, so a traversal reads arbitrary files, such as the admin keyfile, without authentication.
Not startedDockercommit f9ddec4x86_64 · aarch64Secret
Exploit CVE-2017-1000028 to read files from the GlassFish server, then take over the admin console.
The brief for this lab lives in its repository.