A SaltStack 2019.2.3 master, vulnerable to CVE-2020-11651: the ZeroMQ request server on port 4506 accepts unauthenticated calls to ClearFuncs methods such as _prep_auth_info, which leak the root key, which then publishes commands to run on the master.
Pas commencéDockercommit 86c808ax86_64 · aarch64Secret
Exploit CVE-2020-11651 to run commands on the Salt master and read /ctf/flag.
Le brief de ce lab se trouve dans son dépôt.