Skip to content

[Improvement] Unauthorized access to Spring Boot Actuator #4171

Open
@cncaizheng

Description

Search before asking

  • I had searched in the issues and found no similar issues.

Java Version

JDK1.8

Scala Version

2.12.x

StreamPark Version

streampark2.1.4

Flink Version

Flink1.17.1

deploy mode

yarn-application

What happened

Spring Boot Actuator Unauthorized Access Vulnerability

Error Exception

Actor is a functional module provided by springboot for introspection and monitoring of application systems. With the help of Actor, developers can easily view and analyze certain monitoring indicators of the application system. In the case where the actuator is enabled, if relevant permission controls are not properly implemented, unauthorized users can access the default actuator endpoints to obtain monitoring information in the application system.

Screenshots

No response

Are you willing to submit PR?

  • Yes I am willing to submit a PR!(您是否要贡献这个PR?)

Code of Conduct

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions