The H2 2.0.206 web console exposed by a Spring Boot application, vulnerable to CVE-2022-23221: a JDBC URL ending with a backslash breaks the FORBID_CREATION=TRUE suffix the console appends, so an in-memory database opens with an INIT=RUNSCRIPT (or CREATE ALIAS) that runs Java code.
Pas commencéDockercommit 5372b4bx86_64 · aarch64Secret
Exploit CVE-2022-23221 through the H2 console to run commands on the server and get a shell.
Le brief de ce lab se trouve dans son dépôt.