Official Jewel Discussion

The vuln can be hard to find. For what is worth, when a vulnerability has a CVE documented by NVD, it’ll show up after a search here: https://nvd.nist.gov/vuln/search - so worth a shot to see if there are potential candidates in there.
The usual 2cents:
Foothold/User: CVE has a PoC showing the way to generate a valid payload - look at the code to figure out where to use it
Root: while doing your usual check you’ll realize what this is about - and you’re a couple of commands from root