All fixes

Lock down Spring Boot configprops

tech-spring-configprops

The configprops endpoint prints bound configuration, which often includes datasource URLs and API keys. Disable it or require an admin role.

Why this matters

Spring Boot's configprops endpoint exposes configuration properties that may include database URLs and API keys. Conditionally exploitable — depends on whether actual secrets are present in the config.

Spring Boot

  1. 1 Disable the configprops endpoint. It can leak sensitive configuration values.
  2. 2 If you need it for debugging, restrict it to authenticated admin users only
properties
# application.properties
management.endpoints.web.exposure.include=health,info
management.endpoint.configprops.enabled=false

# Or restrict with Spring Security:
# management.endpoints.web.exposure.include=health,info,configprops
# + configure HttpSecurity to require ADMIN role for /actuator/configprops
Spring Boot docs

Does your app still have this?

Scan your domain