The Apache Struts 2.3.34 showcase with an action chaining configuration that has no namespace, vulnerable to S2-057 (CVE-2018-11776): the namespace in the URL is evaluated as OGNL.
Not startedDockercommit 4b21bf1x86_64 · aarch64Secret
Exploit S2-057 (CVE-2018-11776) to run a command on the server.
The brief for this lab lives in its repository.