Описание
Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read environment variables, bean configurations, and storage credentials via actuator endpoints, or modify log levels to suppress logging.
A flaw was found in Zipkin. Unauthenticated attackers can exploit exposed Spring Boot Actuator endpoints on the tracing API port to access sensitive information. This allows them to read environment variables, bean configurations, and storage credentials. Additionally, attackers can modify log levels, potentially suppressing important logging information.
Отчет
An unauthorized access flaw was found in Zipkin. The application exposes Spring Boot Actuator management endpoints directly on the tracing API network port without enforcing authentication or access controls. An unauthenticated remote attacker can exploit these endpoints to extract sensitive runtime configuration details, including environment variables, bean definitions, and storage credentials, or modify log levels to suppress security auditing.
Меры по смягчению последствий
Restrict access to Spring Boot Actuator endpoints by configuring explicit web security authentication rules, or isolate the management port from public exposure by setting management.server.port to a dedicated internal network interface.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Fuse 7 | spring-boot-actuator | Not affected | ||
| Red Hat OpenShift Dev Spaces | devspaces/openvsx-rhel9 | Not affected | ||
| Red Hat OpenShift Dev Spaces | devspaces/pluginregistry-rhel9 | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
8.2 High
CVSS3
Связанные уязвимости
Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read environment variables, bean configurations, and storage credentials via actuator endpoints, or modify log levels to suppress logging.
Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read environment variables, bean configurations, and storage credentials via actuator endpoints, or modify log levels to suppress logging.
8.2 High
CVSS3