Apache Solr 8.2.0 without authentication, vulnerable to CVE-2019-17558: the config API turns on `params.resource.loader.enabled` for the VelocityResponseWriter, and a Velocity template passed in the query then runs commands on the server.
Not startedDockercommit c92293dx86_64 · aarch64Secret
Exploit CVE-2019-17558 to run commands on the Solr server and get a shell.
The brief for this lab lives in its repository.