JBoss Application Server 6.1.0 with the HTTP invoker deployed: /invoker/JMXInvokerServlet deserializes the body of any POST without authentication, so a Commons Collections gadget chain (CVE-2015-7501) runs commands.
Pas commencéDockercommit e317302x86_64 · aarch64Secret
Exploit the JMXInvokerServlet deserialization to run commands on the JBoss server and get a shell.
Le brief de ce lab se trouve dans son dépôt.