Spring Boot Actuator unauthorized access and remote code execution vulnerability

Updated at:
Copy as MD

This document provides remediation steps for the Spring Boot Actuator unauthorized access and remote code execution vulnerability.

Threat description

Actuator is a Spring Boot middleware used for service monitoring and management. Its default configurations can allow unauthorized access to API endpoints. Some endpoints can leak sensitive information, such as website traffic and memory details. An attacker can use features of the Jolokia library to perform remote code execution (RCE) and gain server permissions.

For more information, see the vulnerability details at https://avd.aliyun.com/detail?id=AVD-2021-883345.

Remediation

Solution 1:

You can disable all endpoints by setting the `management.endpoints.enabled` configuration to `false`.

Solution 2:

You can import the `spring-boot-starter-security` dependency and enable the security feature.

1. Add the `spring-boot-starter-security` dependency to the `pom.xml` file of your project.

<dependency>
  <groupId>org.springframework.boot</groupId>
  <artifactId>spring-boot-starter-actuator</artifactId>
</dependency>

2. Enable the security feature by configuring the security settings and access credentials in the `application.properties` file. Then, restart the service for the configuration to take effect. For example:

management.port=8099
management.security.enabled=true
security.user.name=yourUsername
security.user.password=yourPassword

If you encounter any difficulties during this procedure or have other questions, go to Security Center and click 'Need Security Help' to contact a technical support engineer.