Apache Solr 8.11.0 with Log4j 2.14.1, vulnerable to Log4Shell (CVE-2021-44228): a JNDI lookup string logged by the server makes it load and run a class from a remote LDAP or RMI server.
Pas commencéDockercommit e68c5ddx86_64 · aarch64Secret
Exploit CVE-2021-44228 (Log4Shell) to get a shell on the Solr server.
Le brief de ce lab se trouve dans son dépôt.