| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
|
QHelp previews: java/ql/src/Security/CWE/CWE-200/SpringBootActuatorsConfig/SpringBootActuatorsConfig.qhelpExposed Spring Boot actuators in configuration fileSpring Boot includes features called actuators that let you monitor and interact with your web application. Exposing unprotected actuator endpoints through configuration files can lead to information disclosure or even to remote code execution. RecommendationSince actuator endpoints may contain sensitive information, carefully consider when to expose them, and secure them as you would any sensitive URL. If you need to expose actuator endpoints, use Spring Security, which secures actuators by default, or define a custom security configuration. ExampleThe following examples show application.properties configurations that expose sensitive actuator endpoints. # vulnerable configuration (Spring Boot 1.0 - 1.4): exposes endpoints by default
# vulnerable configuration (Spring Boot 1.5): false value exposes endpoints
management.security.enabled=false
# vulnerable configuration (Spring Boot 2.x): exposes all endpoints
management.endpoints.web.exposure.include=*
# vulnerable configuration (Spring Boot 3.x): exposes all endpoints
management.endpoints.web.exposure.include=*
The below configurations ensure that sensitive actuator endpoints are not exposed. # safe configuration (Spring Boot 1.0 - 1.4)
management.security.enabled=true
# safe configuration (Spring Boot 1.5+)
management.security.enabled=true
# safe configuration (Spring Boot 2.x): exposes health and info only by default
management.endpoints.web.exposure.include=health,info
# safe configuration (Spring Boot 3.x): exposes health only by default
management.endpoints.web.exposure.include=health
To use Spring Security, which secures actuators by default, add the spring-boot-starter-security dependency in your Maven pom.xml file. ...
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-actuator</artifactId>
</dependency>
<!-- GOOD: Enable Spring Security -->
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-security</artifactId>
</dependency>
...
References
|
Sorry, something went wrong.
splitting is required to properly test each scenario
Need the existence of an ApplicationProperties File, not an ApplicationProperties ConfigPair
…to align with Spring docs
There was a problem hiding this comment.
This PR promotes the experimental query java/insecure-spring-actuator-config to the main query pack as java/spring-boot-exposed-actuators-config, enabling it to appear in default CodeQL results.
Key changes include:
Copilot reviewed 46 out of 46 changed files in this pull request and generated 1 comment.
Show a summary per file| File | Description |
|---|---|
| java/ql/src/Security/CWE/CWE-200/SpringBootActuatorsConfig/SpringBootActuatorsConfig.ql | New main query implementing the promoted actuator configuration detection |
| java/ql/lib/semmle/code/java/security/SpringBootActuatorsConfigQuery.qll | Core logic library for detecting insecure Spring Boot actuator configurations |
| java/ql/lib/semmle/code/configfiles/ConfigFiles.qll | Added PropertiesFile class to support broader .properties file detection |
| java/ql/test/query-tests/security/CWE-200/semmle/tests/SpringBootActuatorsConfig/ | Comprehensive test suite covering Spring Boot versions 1.x through 3.x |
| java/ql/src/experimental/Security/CWE/CWE-016/ | Removal of experimental query files |
| java/ql/integration-tests/java/query-suite/*.expected | Updated query suite expectations to include the new query |
Sorry, something went wrong.
There was a problem hiding this comment.
Very thorough. One minor request in the change note.
Sorry, something went wrong.
There was a problem hiding this comment.
Looks good from a Docs POV. 👍
Sorry, something went wrong.
| * @problem.severity error | ||
| * @security-severity 6.5 | ||
| * @precision high | ||
| * @id java/spring-boot-exposed-actuators-config |
There was a problem hiding this comment.
Do we need a @previous-id java/insecure-spring-actuator-config tag as well?
Sorry, something went wrong.
There was a problem hiding this comment.
I don't think we are using @previous-id when promoting experimental queries. Only when porting queries from a different query pack.
Sorry, something went wrong.
There was a problem hiding this comment.
I don't think we are using @previous-id when promoting experimental queries. Only when porting queries from a different query pack.
This was my understanding as well.
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
Description
This PR promotes java/insecure-spring-actuator-config from experimental as java/spring-boot-exposed-actuators-config (original PR: #5384).
Consideration
Main changes from the experimental query: