Information Disclosure: Leaked Spring Boot Actuator Environment¶
Identifier:
springboot_actuator_env
Scanner Support¶
| GraphQL Scanner | REST Scanner | WebApp Scanner | ASM Scanner | Automated Pentest |
|---|---|---|---|---|
Description¶
Spring Boot Actuator environment endpoint exposure reveals sensitive environment variables and configuration details, potentially exposing credentials and internal settings.
How we test: We attempt to access Spring Boot Actuator environment endpoints and analyze responses to detect if environment variables and configuration details are exposed. We check if environment endpoints are accessible and if they disclose sensitive information such as credentials, API keys, or internal settings.
Configuration¶
Example¶
Example configuration:
Reference¶
skip¶
Type: boolean
Skip the test if true.