Lock down Spring Boot configprops
tech-spring-configprops
The configprops endpoint prints bound configuration, which often includes datasource URLs and API keys. Disable it or require an admin role.
Why this matters
Spring Boot's configprops endpoint exposes configuration properties that may include database URLs and API keys. Conditionally exploitable — depends on whether actual secrets are present in the config.
Frameworks
Spring Boot
- 1 Disable the configprops endpoint. It can leak sensitive configuration values.
- 2 If you need it for debugging, restrict it to authenticated admin users only
properties
# application.properties
management.endpoints.web.exposure.include=health,info
management.endpoint.configprops.enabled=false
# Or restrict with Spring Security:
# management.endpoints.web.exposure.include=health,info,configprops
# + configure HttpSecurity to require ADMIN role for /actuator/configpropsDoes your app still have this?
Scan your domain