A web application on Apache Shiro 1.2.4, vulnerable to CVE-2016-4437 (Shiro-550): the rememberMe cookie is a serialized Java object encrypted with a hard-coded AES key, so anyone can forge one that carries a gadget chain.
Not startedDockercommit 09b89cbx86_64 · aarch64Secret
Exploit CVE-2016-4437 (Shiro-550) to run a command on the server.
The brief for this lab lives in its repository.