PostgreSQL 10.7 with the superuser postgres / postgres, where COPY ... FROM PROGRAM (CVE-2019-9193, disputed as a feature) runs a shell command as the database server user and reads its output into a table.
Not startedDockercommit 5f28d37x86_64 · aarch64Secret
Log in to PostgreSQL and use COPY FROM PROGRAM (CVE-2019-9193) to run commands and get a shell.
The brief for this lab lives in its repository.