InfluxDB 1.6.6 with HTTP authentication enabled, vulnerable to CVE-2019-20933: the JWT shared secret defaults to empty, so a JWT signed with an empty key for an existing user (admin) passes authentication and runs queries.
Not startedDockercommit 25affadx86_64 · aarch64Secret
Exploit CVE-2019-20933 to forge a JWT, query InfluxDB as admin and read the flag.
The brief for this lab lives in its repository.