Apache Druid 0.20.0, vulnerable to CVE-2021-25646: a crafted ingestion spec re-enables the disabled JavaScript engine through an empty JSON key, so an unauthenticated request runs JavaScript, and therefore commands, on the server.
Pas commencéDockercommit 28fe54dx86_64 · aarch64Secret
Exploit CVE-2021-25646 to run commands on the Druid server and read /ctf/flag.
Le brief de ce lab se trouve dans son dépôt.