A Spring Cloud Function 3.2.2 application, vulnerable to CVE-2022-22963: a request to /functionRouter with a spring.cloud.function.routing-expression header has that header evaluated as a SpEL expression, which runs commands.
Pas commencéDockercommit d9069c1x86_64 · aarch64Secret
Exploit CVE-2022-22963 to run commands on the Spring server and get a shell.
Le brief de ce lab se trouve dans son dépôt.