-
Notifications
You must be signed in to change notification settings - Fork 180
Open
Description
While doing a vulnerable lab the scanner detected RCE using CommonsCollections3 alt payloads 3 and 4 with gzip and base64. Exploitation was failing. A colleague suggested I brute force the library instead of trusting the scan results and I ended up exploiting the lab with CommonsCollections6.
I don't know a ton about java, or these libs, but I wanted to make an issue for this and dig into it, sharing my findings here for others that run into this issue.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels