A Spring WebMVC 5.3.17 application on Tomcat and JDK 9+, vulnerable to Spring4Shell (CVE-2022-22965): data binding reaches the class loader, so request parameters can rewrite Tomcat's access log into a web shell.
Pas commencéDockercommit f8ca4bdx86_64 · aarch64Secret
Exploit CVE-2022-22965 (Spring4Shell) to get a shell on the server.
Le brief de ce lab se trouve dans son dépôt.