InfluxDB 1.6.6 with HTTP authentication enabled, vulnerable to CVE-2019-20933: the JWT shared secret defaults to empty, so a JWT signed with an empty key for an existing user (admin) passes authentication and runs queries.
Pas commencéDockercommit 25affadx86_64 · aarch64Secret
Exploit CVE-2019-20933 to forge a JWT, query InfluxDB as admin and read the flag.
Le brief de ce lab se trouve dans son dépôt.