Vulhub
Vulhub is an open-source collection of pre-built vulnerable docker environments for security researchers and educators.
# Clone the repository
git clone --depth 1 https://github.com/vulhub/vulhub.git
# Enter the directory
cd vulhub/spring/CVE-2022-22947
# Start the environment
docker compose up -d
Why Use Vulhub?
Docker Based
All environments are built with Docker and Docker Compose, making them easy to deploy and isolate.
Real Vulnerabilities
Practice with real-world vulnerabilities in a safe, controlled environment for learning and research.
Well Documented
Each vulnerability comes with detailed documentation explaining the vulnerability and exploitation steps.
Latest Environments
View all environmentsTomcat Session Deserialization Remote Code Execution
Explore the Tomcat Session Deserialization Remote Code Execution vulnerability and learn how to exploit it.
Apache HertzBeat SnakeYaml Deserialization Remote Code Execution
Explore the Apache HertzBeat SnakeYaml Deserialization Remote Code Execution vulnerability and learn how to exploit it.
Kibana 7.6.2 upgrade-assistant-telemetry Prototype Pollution Leads to RCE
Explore the Kibana 7.6.2 upgrade-assistant-telemetry Prototype Pollution Leads to RCE vulnerability and learn how to exploit it.
GlassFish 4.1.0 Arbitrary File Read
Explore the GlassFish 4.1.0 Arbitrary File Read vulnerability and learn how to exploit it.
FFmpeg AVI Arbitrary File Read
Explore the FFmpeg AVI Arbitrary File Read vulnerability and learn how to exploit it.
Apache HugeGraph JWT Token Secret Hardcoding Leads to Authentication Bypass
Explore the Apache HugeGraph JWT Token Secret Hardcoding Leads to Authentication Bypass vulnerability and learn how to exploit it.
Ready to start your security research?
Explore our collection of vulnerable environments and enhance your security skills today.