JBoss AS 6.1.0, vulnerable to CVE-2017-12149: the HTTP invoker's ReadOnlyAccessFilter deserializes the body of any request to /invoker/readonly without checks, so a Java gadget chain runs commands.
Not startedDockercommit e3c3290x86_64 · aarch64Secret
Exploit CVE-2017-12149 to run a command on the JBoss server.
The brief for this lab lives in its repository.