OpenTSDB 2.4.0, vulnerable to CVE-2020-35476: the yrange parameter of the /q graph endpoint goes unescaped into a Gnuplot script, where `system()` runs a shell command.
Pas commencéDockercommit 03f9766x86_64 · aarch64Secret
Exploit CVE-2020-35476 to run commands on the OpenTSDB server and get a shell.
Le brief de ce lab se trouve dans son dépôt.