A Ruby on Rails 5.2.2 application with a controller that calls render file:, vulnerable to CVE-2019-5418: the Accept header becomes part of the template lookup, so Accept: ../../../../etc/passwd{{ reads files from the server.
Not startedDockercommit 67a77bax86_64 · aarch64Secret
Exploit CVE-2019-5418 to read files from the Rails server and read the flag.
The brief for this lab lives in its repository.