Skip to content
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Java: adjust metadata and alert msg
  • Loading branch information
Jami Cogswell authored and Jami Cogswell committed Jul 18, 2025
commit ea529b047b0223d025b0009fb95c944196a71da8
Original file line number Diff line number Diff line change
@@ -1,14 +1,14 @@
/**
* @name Insecure Spring Boot Actuator Configuration
* @description Exposed Spring Boot Actuator through configuration files without declarative or procedural
* security enforcement leads to information leak or even remote code execution.
* @name Exposed Spring Boot actuators in configuration file
* @description Exposing Spring Boot actuators through configuration files may lead to information leak from
* the internal application, or even to remote code execution.
* @kind problem
* @problem.severity error
* @security-severity 6.5
* @precision high
* @id java/insecure-spring-actuator-config
* @id java/spring-boot-exposed-actuators-config
* @tags security
* experimental
* external/cwe/cwe-016
* external/cwe/cwe-200
*/

import java
Expand All @@ -21,5 +21,5 @@ where
// TODO: remove pom; for debugging versions
d = pom.getADependency()
select d,
"Insecure $@ of Spring Boot Actuator exposes sensitive endpoints (" +
"Insecure Spring Boot actuator $@ exposes sensitive endpoints (" +
pom.getParentElement().getVersionString() + ").", jpOption, "configuration"