Hunt Springboot

Hunt Spring Boot specific vulnerabilities — Actuator endpoints (heapdump, env, loggers, mappings, shutdown), Spring Expression Language (SpEL) injection → RCE, H2 console RCE, Jolokia JMX exposure, Spring4Shell (CVE-2022-22965), Spring Cloud Function SPEL (CVE-2022-22963), heap dump credential extraction. Use when target runs Spring Boot — detected via X-Application-Context header, /actuator, Whitelabel Error Page, or Java stack traces.

zyrexnn ae6dbef 9.0 KB Updated

File contents

zyrexnn/cybermes/tree/main/skills/hunt-springboot commit ae6dbef75b

Frequently asked questions

npx skillmds@latest add zyrexnn/hunt-springboot