Redis 5.0.7 built against the Debian/Ubuntu dynamic Lua library, without authentication, vulnerable to CVE-2022-0543: the `package` global is left in the Lua sandbox, so EVAL can call package.loadlib to load luaopen_io and run shell commands.
Not startedDockercommit d8e2f00x86_64 · aarch64Secret
Exploit CVE-2022-0543 with an EVAL script to escape the Lua sandbox and run commands on the Redis server.
The brief for this lab lives in its repository.