References https://zhuanlan.zhihu.com/p/602691208 https://www.cnblogs.com/wsx2019/p/17453170.html https://developer.aliyun.com/article/1079170 https://blog.csdn.net/weixin_39190897/article/details/136245568 https://www.nowcoder.com/discuss/396603397997162496 https://www.wangsu.com/news/content/blog/3741 https://cloud.tencent.com/developer/article/2070446 https://github.com/rabbitmask/SB-Actuator https://zhuanlan.zhihu.com/p/407710777 https://zone.huoxian.cn/d/738-spring-boot https://rivers.chaitin.cn/blog/cq940510lnechd242kvg https://comate.baidu.com/zh/page/nm7750vyl7i https://blog.csdn.net/weixin_44106034/article/details/133934404 https://www.secevery.com/toAticleInfo?id=e4f20aebaa4ae0a4a3d010380f5fc35f https://apifox.com/apiskills/how-to-use-spring-boot-actuator-2/ https://github.com/LandGrey/SpringBootVulExploit https://developer.aliyun.com/article/1586318 https://r0yanx.com/2020/06/05/Spring-Boot-Actuators%E6%9C%AA%E6%8E%88%E6%9D%83GetShell/ https://www.yisu.com/zixun/729033.html https://www.wiz.io/blog/spring-boot-actuator-misconfigurations https://docs.stackhawk.com/vulnerabilities/40042/ https://www.invicti.com/web-application-vulnerabilities/spring-boot-actuator https://www.acunetix.com/vulnerabilities/web/spring-boot-misconfiguration-all-spring-boot-actuator-endpoints-are-web-exposed/
Related VulnerabilitiesNacos /nacos/actuator 未授权访问漏洞SpringBlade /api/blade-log/api/list SQL 注入漏洞SpringBlade /api/blade-user/list SQL 注入漏洞PoCspringboot-sbom: Spring Boot Actuator SBOM - ExposurePoCCVE-2025-41242: Spring Framework - Path TraversalPoCspringboot-httpexchanges: Detects Springboot HTTP Exchanges ActuatorPoCCVE-2024-38819: Spring Framework Path Traversal in Functional Web FrameworksPentaho /pentaho/j_spring_security_check 默认口令漏洞PoCCVE-2026-22739: Spring Cloud Config Server - Path TraversalPoCspringboot-x-application-context: Spring Boot `X-Application-Context` Header ExposureSpring Framework路径遍历漏洞(CVE-2024-38819)Spring Cloud Gateway SpEL 表达式注入漏洞