Lock down Spring Boot Actuator
exposed-actuator
Spring Boot Actuator endpoints are reachable without a login. They confirm your stack and expose runtime detail, so put them behind auth.
Why this matters
Your Spring Boot health endpoint is publicly accessible. It confirms the framework and may expose service names — reconnaissance data, not directly exploitable.
Frameworks
Spring Boot
- 1 Restrict actuator endpoints to authenticated users or internal networks
java
# application.properties
management.endpoints.web.exposure.include=health,info
management.endpoint.health.show-details=when-authorized
# Or secure with Spring Security
@Bean
SecurityFilterChain actuatorSecurity(HttpSecurity http) throws Exception {
http.securityMatcher("/actuator/**")
.authorizeHttpRequests(auth -> auth.anyRequest().hasRole("ADMIN"));
return http.build();
}Does your app still have this?
Scan your domain