Supervisord 3.3.2 with an open inet_http_server, vulnerable to CVE-2017-11610: the XML-RPC dispatcher walks dotted method names through module attributes, so a call like supervisor.supervisord.options.warnings.linecache.os.system runs commands.
Pas commencéDockercommit c0c87f6x86_64 · aarch64Secret
Exploit CVE-2017-11610 to run commands through Supervisord and read /ctf/flag.
Le brief de ce lab se trouve dans son dépôt.