A Ruby on Rails 5.0.7 application in development mode with Sprockets 3.7.1, vulnerable to CVE-2018-3760: the /assets/file:// handler checks the path before a second URL decoding, so %252e%252e/ sequences under an allowed asset folder read any file on the server.
Pas commencéDockercommit 2efaf41x86_64 · aarch64Secret
Exploit CVE-2018-3760 to read files outside the Rails asset paths and read /ctf/flag.
Le brief de ce lab se trouve dans son dépôt.