Supervisord 3.3.2 with an open inet_http_server, vulnerable to CVE-2017-11610: the XML-RPC dispatcher walks dotted method names through module attributes, so a call like supervisor.supervisord.options.warnings.linecache.os.system runs commands.
Not startedDockercommit 9725206x86_64 · aarch64Secret
Exploit CVE-2017-11610 to run commands through Supervisord and get a shell.
The brief for this lab lives in its repository.