Spring Boot Actuator Detected

info Web App Scanning Plugin ID 113195

Synopsis

Spring Boot Actuator Detected

Description

This is an informational notice that the scanner was able to detect an accessible Spring Actuator. Actuator endpoints let you monitor and interact with your application. Spring Boot includes a number of built-in endpoints and lets you add your own. For example, the 'health' endpoint provides basic application health information.

Solution

Disable unnecessary endpoints and do not make sensitive endpoints externally accessible, limiting access to known IP Addresses.

See Also

https://docs.spring.io/spring-boot/docs/current/reference/html/actuator.html

Plugin Details

Severity: Info

ID: 113195

Type: remote

Published: 3/24/2022

Updated: 3/13/2023

Scan Template: api, basic, full, pci, scan