All fixes

Disable the Spring mappings endpoint

tech-spring-mappings

The mappings endpoint lists every route, including internal ones you never linked. Stop exposing it, or put the whole actuator behind auth.

Why this matters

Spring Boot's mappings endpoint lists URL routes including internal endpoints — reconnaissance data, not directly exploitable.

Spring Boot

  1. 1 Restrict actuator endpoint exposure. Mappings should not be public.
properties
# application.properties
management.endpoints.web.exposure.include=health,info
management.endpoint.mappings.enabled=false
Spring Boot docs

Does your app still have this?

Scan your domain