Apache Solr 7.0.1 without authentication, vulnerable to CVE-2017-12629: the config API adds a RunExecutableListener whose command runs when the core commits an update.
Not startedDockercommit 15dd037x86_64 · aarch64Secret
Exploit CVE-2017-12629 to run commands on the Solr server and get a shell.
The brief for this lab lives in its repository.