Apache APISIX 2.11.0 with the admin API reachable from any address and the default X-API-KEY edd1c9f034335f136f87ad84b625c8f1 (CVE-2020-13945): the key creates routes, and a route's script parameter is Lua code executed by the gateway on each request.
Pas commencéDockercommit 7e49ea1x86_64 · aarch64Secret
Exploit CVE-2020-13945 (the default APISIX admin key) to run commands on the gateway and read /ctf/flag.
Le brief de ce lab se trouve dans son dépôt.