logo

Volkswagen massive data leak through Spring Boot Actuator misconfiguration (Incident)

ID: a838cda0-f9b2-5183-b892-068966c35508

STIX ID: report--a838cda0-f9b2-5183-b892-068966c35508

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2024-12-30

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers discovered a misconfigured Spring Boot Actuator endpoint in Volkswagen's environment that exposed a Java heap dump; the heap dump contained active AWS credentials in plaintext, found using tools like Subfinder and GoBuster, and detailed in linked research and blog posts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.