Apache Tomcat 9.0.30 with the AJP connector on port 8009, vulnerable to CVE-2020-1938 (Ghostcat): AJP request attributes set javax.servlet.include.* values, so a client reads any file in a web application, such as WEB-INF/web.xml, or includes it as a JSP.
Not startedDockercommit 2f00e77x86_64 · aarch64Secret
Exploit CVE-2020-1938 (Ghostcat) to read files from the Tomcat web application and read the flag.
The brief for this lab lives in its repository.