An Apache Dubbo 2.7.3 provider exposing a service over the http protocol (Spring HttpInvoker), vulnerable to CVE-2019-17564: a POST to the service path is deserialized with ObjectInputStream, so a Commons Collections gadget chain runs commands.
Pas commencéDockercommit 70f8944x86_64 · aarch64Secret
Find the Dubbo service path and exploit CVE-2019-17564 to run commands on the provider.
Le brief de ce lab se trouve dans son dépôt.