Apache Solr 8.2.0 without authentication, vulnerable to CVE-2019-17558: the config API turns on `params.resource.loader.enabled` for the VelocityResponseWriter, and a Velocity template passed in the query then runs commands on the server.
Pas commencéDockercommit 531e2ffx86_64 · aarch64Secret
Exploit CVE-2019-17558 to run commands on the Solr server and read /ctf/flag.
Le brief de ce lab se trouve dans son dépôt.