Detects Springboot HTTP Exchanges Actuator
The exposed httpexchanges endpoint can leak recent HTTP request/response data, including URIs, headers, and status codes.
共找到 23 条公开漏洞记录
The exposed httpexchanges endpoint can leak recent HTTP request/response data, including URIs, headers, and status codes.
Spring Boot Actuator SBOM endpoint was detected and is exposed without authentication. The endpoint returns a Software Bill of Materials (typically CycloneDX or SPDX JSON) listing every dependency and version shipped with the application, which lets an attacker enumerate the exact library inventory and trivially map it to known CVEs for targeted exploitation.
Detected the presence of the X-Application-Context header in HTTP responses, which can expose sensitive application context information.
Spring Boot LoggerConfig Actuator panel was detected.
Spring Boot Auditevents Actuator panel was detected.
Spring Boot Status Actuator panel was detected.
Spring Boot Scheduledtasks Actuator panel was detected.
Spring Boot Health Actuator panel was detected.
Spring Boot information panel displaying app name, version information, and other values was detected.
Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable when all the following are true: * The application is using Spring Cloud Gateway Server Webflux (Spring Cloud Gateway Server WebMVC is not vulnerable). * Spring Boot actuator is a dependency. * The Spring Cloud Gateway Server Webflux actuator web endpoint is enabled via management.endpoints.web.exposure.include=gateway. * The actuator endpoints are available to attackers. * The actuator endpoints are unsecured.
OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, insufficient path traversal mechanisms make absolute path traversal possible. This vulnerability allows unauthorized access to sensitive internal files. Commit c835c6f7799eacada4c0fc77e0816f250af01ad2 contains a patch for the issue.
Displays a complete list of all the Spring beans in the application
Displays an auto-configuration report showing all auto-configuration candidates and the reason why they 'were' or 'were not' applied.
The caches endpoint provides access to the application's caches.
A Spring Boot Actuator heap dump was detected. A heap dump is a snapshot of JVM memory, which could expose environment variables and HTTP requests.
Spring Boot is susceptible to remote code execution via Apache Log4j.
spring-boot-actuator-logview before version 0.2.13 contains a directory traversal vulnerability in libraries that adds a simple logfile viewer as a spring boot actuator endpoint (maven package "eu.hinsch:spring-boot-actuator-logview".