Skip to main content
CyberConfirmedHighDevelopingFeatured
10.0

Widespread exploitation of exposed Spring Boot /actuator/heapdump endpoints

Threat actors are actively scanning for and exploiting misconfigured Spring Boot applications that expose the /actuator/heapdump endpoint. This vulnerability allows unauthorized access to memory dumps containing sensitive credentials, including API keys and database passwords, posing a significant risk of lateral movement and data exfiltration.

SANS Internet Storm Centerabout 4 hours agoCredibility 60%View source

Score Breakdown

Mosaic Score10.0
Confidence0.9
Significance0.8
Source credibility0.6
Source

Related signals

8 found