Hunt Springboot

Hunt Spring Boot specific vulnerabilities — Actuator endpoints (heapdump, env, loggers, mappings, shutdown), Spring Expression Language (SpEL) injection → RCE, H2 console RCE, Jolokia JMX exposure, Spring4Shell (CVE-2022-22965), Spring Cloud Function SPEL (CVE-2022-22963), heap dump credential extraction. Use when target runs Spring Boot — detected via X-Application-Context header, /actuator, Whitelabel Error Page, or Java stack traces.

elementalsouls cb9cb09 10.4 KB Updated

File contents

elementalsouls/Claude-BugHunter commit cb9cb091fd

Frequently asked questions

npx skillmds@latest add elementalsouls/hunt-springboot