Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-82265

Опубликовано: 28 авг. 2026
Источник: redhat
CVSS3: 8.2

Описание

Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read environment variables, bean configurations, and storage credentials via actuator endpoints, or modify log levels to suppress logging.

A flaw was found in Zipkin. Unauthenticated attackers can exploit exposed Spring Boot Actuator endpoints on the tracing API port to access sensitive information. This allows them to read environment variables, bean configurations, and storage credentials. Additionally, attackers can modify log levels, potentially suppressing important logging information.

Отчет

An unauthorized access flaw was found in Zipkin. The application exposes Spring Boot Actuator management endpoints directly on the tracing API network port without enforcing authentication or access controls. An unauthenticated remote attacker can exploit these endpoints to extract sensitive runtime configuration details, including environment variables, bean definitions, and storage credentials, or modify log levels to suppress security auditing.

Меры по смягчению последствий

Restrict access to Spring Boot Actuator endpoints by configuring explicit web security authentication rules, or isolate the management port from public exposure by setting management.server.port to a dedicated internal network interface.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7spring-boot-actuatorNot affected
Red Hat OpenShift Dev Spacesdevspaces/openvsx-rhel9Not affected
Red Hat OpenShift Dev Spacesdevspaces/pluginregistry-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-306
https://bugzilla.redhat.com/show_bug.cgi?id=2525690zipkin: org.springframework.boot/spring-boot-actuator: Zipkin: Information disclosure via unauthenticated Spring Boot Actuator endpoints

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
19 дней назад

Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read environment variables, bean configurations, and storage credentials via actuator endpoints, or modify log levels to suppress logging.

CVSS3: 6.5
github
19 дней назад

Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read environment variables, bean configurations, and storage credentials via actuator endpoints, or modify log levels to suppress logging.

8.2 High

CVSS3