CVE Tools

HTB DevArea. Обходим проверку символических ссылок в Linux

Хакер (xakep.ru)By RalfHacker

ResearchDevArea

Our summary

A new Hack The Box “DevArea” case study demonstrates how attackers can chain vulnerabilities to reach superuser access on a Linux target by abusing file-reading and proxy-related weaknesses. It highlights Apache CXF (SSRF) issues tracked as CVE-2022-46364, affecting versions up to 3.5.2 and 3.4.9, and pairs them with Hoverfly remote code execution leading to CVE-2025-54123 (requiring credentials in the described scenario). The takeaway is that SSRF flaws and insecure testing/proxy components can combine to leak sensitive data and escalate impact well beyond initial access.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store