Lock down the Actuator env endpoint
exposed-actuator-env
The Actuator env endpoint prints your whole configuration, datasource URLs, passwords and API keys included. Disable it or require an admin role.
Why this matters
Your Spring Boot environment endpoint is publicly accessible. It exposes database URLs, API keys, and secrets from your application configuration.
Frameworks
Spring Boot
- 1 Immediately disable the env endpoint in production
- 2 It exposes environment variables including secrets
properties
# application.properties
management.endpoint.env.enabled=false
management.endpoints.web.exposure.include=health,infoDoes your app still have this?
Scan your domain