Apache Tomcat 8.5.19 with the default servlet's readonly set to false, vulnerable to CVE-2017-12615: an HTTP PUT with a crafted file name writes a JSP file to the web root.
Not startedDockercommit ad480f5x86_64 · aarch64Secret
Exploit CVE-2017-12615 to upload a JSP web shell and run a command on the server.
The brief for this lab lives in its repository.