zlt2000 Microservices-Platform Spring Actuator Interface Information Disclosure Vulnerability

Vulnerability

A vulnerability allowing information disclosure has been identified in zlt2000 microservices-platform versions prior to 6.0.0. This issue arises from the Spring Actuator Interface, specifically in the file '/actuator', which lacks proper access controls. As a result, any user can remotely access and retrieve various sensitive data, including configurations and environment variables, from the affected microservices.

Impact

Exploitation of this vulnerability allows unauthorized users to access sensitive information from the affected microservices, potentially including confidential configurations and environment variables.

Reproduction

The vulnerability can be reproduced by sending a request to the '/actuator' endpoint of any microservice running on the affected platform. This can be done using a web browser or a tool like curl, targeting the appropriate port where the microservice is running.

Remediation

It is recommended to apply restrictive firewall rules to block unauthorized access to the '/actuator' endpoints. Additionally, consider updating to a version of zlt2000 microservices-platform that includes the necessary access controls for Spring Actuator interfaces.

Added: Aug 8, 2025, 8:17 PM
Updated: Aug 8, 2025, 8:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.