logo

Under the Radar: Exploring Spring Boot Actuator Misconfigurations

ID: b1b14603-7ac8-540b-b953-c4fc7919dcd8

STIX ID: report--b1b14603-7ac8-540b-b953-c4fc7919dcd8

Feed Name: Wiz Blog

Threat Score
78/100

Date Published: 2024-12-16

Date Updated: 2026-05-01

...
...

This report examines widespread misconfigurations of Spring Boot Actuator endpoints (heapdump, env, gateway) that can expose sensitive configuration and credentials and, when combined with vulnerable Spring Cloud Gateway versions, enable remote code execution (CVE-2022-22947). It documents prevalence metrics, observed scanning activity, step-by-step proof-of-concept abuse (including exfiltrating AWS instance metadata), and recommended mitigations such as disabling sensitive endpoints, enforcing authentication, and applying secure defaults.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.