漏洞描述 pring-boot-actuator-logview 在一个库中添加了一个简单的日志文件查看器作为 spring boot 执行器端点。它是 maven包“eu.hinsch:spring-boot-actuator-logview”。
相关漏洞推荐 Spring Cloud Gateway 信息泄露漏洞(CVE-2025-41243) Spring Cloud Gateway环境属性修改漏洞 (CVE-2025-41243) CVE-2019-3799: Spring Cloud Config Server Directory Traversal springboot-actuator-unauth: Springboot Actuator Unauth springblade-export-user-sqli: SpringBlade 框架后台 export-user 路径 SQL 注入漏洞 POC spring4shell-CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+ POC CVE-2016-4977: Spring Security OAuth2 Remote Command Execution POC CVE-2017-8046: Spring Data REST < 2.6.9 (Ingalls SR9) / 3.0.1 (Kay SR1) - PATCH Request Remote Code Execution POC CVE-2018-1271: Spring MVC Framework - Local File Inclusion POC CVE-2018-1273: Spring Data Commons - Remote Code Execution POC CVE-2019-3799: Spring Cloud Config Server - Local File Inclusion POC CVE-2020-5405: Spring Cloud Config - Local File Inclusion POC CVE-2020-5410: Spring Cloud Config Server - Local File Inclusion