Elasticsearch 1.1.1 without authentication, vulnerable to CVE-2014-3120: dynamic scripting is enabled by default, so the script_fields of a search request hold an MVEL expression that calls Java classes and runs commands.
Pas commencéDockercommit 3a22efbx86_64 · aarch64Secret
Exploit CVE-2014-3120 with a search request to run commands on the Elasticsearch server and get a shell.
Le brief de ce lab se trouve dans son dépôt.