All fixes

Lock down the Actuator env endpoint

exposed-actuator-env

The Actuator env endpoint prints your whole configuration, datasource URLs, passwords and API keys included. Disable it or require an admin role.

Why this matters

Your Spring Boot environment endpoint is publicly accessible. It exposes database URLs, API keys, and secrets from your application configuration.

Spring Boot

  1. 1 Immediately disable the env endpoint in production
  2. 2 It exposes environment variables including secrets
properties
# application.properties
management.endpoint.env.enabled=false
management.endpoints.web.exposure.include=health,info

Does your app still have this?

Scan your domain