漏洞描述 Actuator是Spring Boot提供的服务监控和管理中间件,当 /env、/restart 端点允许POST方式进行访问,通过修改logging.config 属性的值可能触发远程命令执行漏洞。
相关漏洞推荐 springboot-actuator-unauth: Springboot Actuator Unauth POC CVE-2025-46822: Java-springboot-codebase 1.1 - Arbitrary File Read POC multi-region-logging-disabled: Global Service (Multi-Region) Logging - Disabled POC cloudfront-logging-disabled: Cloudfront Logging Disabled POC cloudtrail-s3-bucket-logging: CloudTrail S3 Logging POC eks-cluster-logging: Kubernetes Cluster Logging POC eks-logging-kubes-api-calls: Enable CloudTrail Logging for Kubernetes API Calls POC s3-access-logging: S3 Bucket - Access Logging Not Enabled POC azure-blob-service-logging-disabled: Azure Storage Blob Service Logging Not Enabled POC azure-storage-queue-logging-disabled: Azure Storage Queue Logging Not Enabled POC azure-storage-table-logging-disabled: Azure Storage Table Logging Not Enabled POC gcloud-gke-logging-disabled: GKE Clusters Without Cloud Logging Enabled POC gcloud-https-lb-logging-disabled: Logging Disabled on HTTP(S) Load Balancers