Apache JMeter 3.3 running as a jmeter-server, vulnerable to CVE-2018-1297: its RMI registry on port 1099 deserializes objects from any client, and the BeanShell gadget chain bundled with JMeter runs commands.
Not startedDockercommit 20281b8x86_64 · aarch64Secret
Exploit CVE-2018-1297 through the JMeter RMI registry to run commands and get a shell.
The brief for this lab lives in its repository.