References https://www.wangsu.com/news/content/blog/3741 https://blog.csdn.net/JHIII/article/details/126601858 https://comate.baidu.com/zh/page/imnmm1rh6ca https://zhuanlan.zhihu.com/p/602691208 https://github.com/pig-mesh/pig/issues/977 https://zone.huoxian.cn/d/2924-spring-boot https://www.cnkirito.moe/spring-boot-actuator-notes/ https://www.cnblogs.com/shamo89/p/17988088 https://rivers.chaitin.cn/blog/cqguunh0lne7jdu9ufk0 https://blog.zgsec.cn/archives/129.html https://cloud.tencent.com/developer/article/1816814 https://zhuanlan.zhihu.com/p/561679203 https://github.com/LandGrey/SpringBootVulExploit https://cametom006.medium.com/how-i-found-and-bypassed-a-spring-boot-actuator-information-disclosure-bug-c4930b740a50 https://www.wiz.io/blog/spring-boot-actuator-misconfigurations https://c4ng4c31r0.medium.com/sensitive-information-disclosure-via-spring-boot-default-paths-74f60f5d4a84 https://docs.escape.tech/documentation/reference/vulnerabilities/springboot_actuator_env/ https://hacktricks.wiki/en/network-services-pentesting/pentesting-web/spring-actuators.html https://www.acunetix.com/vulnerabilities/web/spring-boot-actuator/
Related VulnerabilitiesNacos /nacos/actuator 未授权访问漏洞Spring Actuator 未授权访问漏洞PoCspringboot-sbom: Spring Boot Actuator SBOM - ExposurePoCspringboot-httpexchanges: Detects Springboot HTTP Exchanges ActuatorPoCspringboot-x-application-context: Spring Boot `X-Application-Context` Header Exposurespringboot-actuator-unauth: Springboot Actuator UnauthPoCCVE-2021-21234: Spring Boot Actuator Logview Directory TraversalPoCCVE-2025-34026: Versa Concerto Actuator Endpoint - Authentication BypassPoCCVE-2025-46822: Java-springboot-codebase 1.1 - Arbitrary File ReadPoCspringboot-admin-unauth: Spring boot Admin unauthPoCspringboot-h2-db-rce: Spring Boot H2 Database RCEPoChikvision-env: Hikvision Springboot Env Actuator - Detect