A Ruby on Rails 5.0.7 application in development mode with Sprockets 3.7.1, vulnerable to CVE-2018-3760: the /assets/file:// handler checks the path before a second URL decoding, so %252e%252e/ sequences under an allowed asset folder read any file on the server.
Not startedDockercommit dceb463x86_64 · aarch64Secret
Exploit CVE-2018-3760 to read files outside the Rails asset paths and read the flag.
The brief for this lab lives in its repository.