CVE Tools
Back to feed
Research DevArea privilege-escalation Ubuntu web-app

HTB DevArea. Обходим проверку символических ссылок в Linux

Хакер (xakep.ru)·By RalfHacker··4 min read
CVE Tools coverage

A new Hack The Box “DevArea” case study demonstrates how attackers can chain vulnerabilities to reach superuser access on a Linux target by abusing file-reading and proxy-related weaknesses. It highlights Apache CXF (SSRF) issues tracked as CVE-2022-46364, affecting versions up to 3.5.2 and 3.4.9, and pairs them with Hoverfly remote code execution leading to CVE-2025-54123 (requiring credentials in the described scenario). The takeaway is that SSRF flaws and insecure testing/proxy components can combine to leak sensitive data and escalate impact well beyond initial access.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store