Open
Description
While doing a vulnerable lab the scanner detected RCE using CommonsCollections3
alt payloads 3 and 4 with gzip and base64. Exploitation was failing. A colleague suggested I brute force the library instead of trusting the scan results and I ended up exploiting the lab with CommonsCollections6
.
I don't know a ton about java, or these libs, but I wanted to make an issue for this and dig into it, sharing my findings here for others that run into this issue.
Metadata
Metadata
Assignees
Labels
No labels