Spring Security OAuth 2.0.8, vulnerable to CVE-2016-4977: when /oauth/authorize fails, the whitelabel error view evaluates ${...} found in the error message, which contains the user-supplied response_type, so a logged-in user runs SpEL and therefore commands.
Not startedDockercommit 3b85723x86_64 · aarch64Secret
Exploit CVE-2016-4977 on the /oauth/authorize endpoint to run commands and get a shell.
The brief for this lab lives in its repository.