Apache Unomi 1.5.1 with Elasticsearch 7.9.3, vulnerable to CVE-2020-13942 (a bypass of the CVE-2020-11975 fix): a condition in a /context.json request carries an MVEL script or OGNL expression that Unomi evaluates without restriction, so an unauthenticated request runs commands.
Pas commencéDockercommit 0be1d68x86_64 · aarch64Secret
Exploit CVE-2020-13942 with a crafted /context.json request to run commands on the Unomi server and get a shell.
Le brief de ce lab se trouve dans son dépôt.