All fixes

Lock down Spring Boot Actuator

exposed-actuator

Spring Boot Actuator endpoints are reachable without a login. They confirm your stack and expose runtime detail, so put them behind auth.

Why this matters

Your Spring Boot health endpoint is publicly accessible. It confirms the framework and may expose service names — reconnaissance data, not directly exploitable.

Spring Boot

  1. 1 Restrict actuator endpoints to authenticated users or internal networks
java
# application.properties
management.endpoints.web.exposure.include=health,info
management.endpoint.health.show-details=when-authorized

# Or secure with Spring Security
@Bean
SecurityFilterChain actuatorSecurity(HttpSecurity http) throws Exception {
    http.securityMatcher("/actuator/**")
        .authorizeHttpRequests(auth -> auth.anyRequest().hasRole("ADMIN"));
    return http.build();
}
Spring Boot docs

Does your app still have this?

Scan your domain