A SOAP web service on Apache CXF 3.2.14 using Aegis DataBinding, vulnerable to CVE-2024-28752: an `xop:Include` element with a URL makes the server fetch it (SSRF), including `file://` URLs, and echo the content back.
Pas commencéDockercommit e39b5afx86_64 · aarch64Secret
Exploit CVE-2024-28752 to make the CXF service read a local file and read /ctf/flag.
Le brief de ce lab se trouve dans son dépôt.