Apache Solr 7.0.1 without authentication, vulnerable to CVE-2017-12629: the config API adds a RunExecutableListener whose command runs when the core commits an update.
Pas commencéDockercommit 6fe14c9x86_64 · aarch64Secret
Exploit CVE-2017-12629 to run commands on the Solr server and read /ctf/flag.
Le brief de ce lab se trouve dans son dépôt.