Summary #

Spring Boot Actuator endpoints let you monitor and interact with your application. Spring Boot includes a number of built-in endpoints and lets you add your own.

By default, all endpoints but shutdown are enabled but only health and info are exposed.

This web application is configured with management.endpoints.web.expose=* or management.endpoints.web.exposure.include=* that is exposing all Spring Boot Actuator endpoints.

Impact #

Some Actuator endpoints like the heapdump endpoint disclose very sensitive information such as the heap dump. Make sure you restrict access to these endpoints to prevent abuse.

Actions To Take #

Make sure you only enable the Spring Boot Actuator endpoints that you really need and restrict access to these endpoints.

It's recommended to enable security for Spring Boot Actuator endpoints using the following configuration (in the Spring properties file):
Classifications #
CWE-16; OWASP 2013-A5; OWASP 2017-A6 , CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
Vulnerability Index

Vulnerability Index

You can search and find all vulnerabilities


Search Vulnerability


Dead accurate, fast & easy-to-use Web Application Security Scanner

Get a demo