You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Cloud配置服务器通过Actuator端点泄露Git环境问题求助

问题描述

搭建Spring Cloud Config Server时,仅配置了必要依赖与@EnableConfigServer注解,配置源为Git,同时启用Actuator并仅暴露health端点。但访问任意(包括不存在的)Actuator端点(如/actuator/foo-bar)时,服务器会返回完整的Git配置源(包含敏感信息);移除@EnableConfigServer注解后,Actuator恢复正常。请问这是配置错误还是安全漏洞?

相关配置

POM依赖

<parent>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-parent</artifactId>
    <version>2.7.3</version>
    <relativePath /> <!-- lookup parent from repository -->
</parent>
<groupId>cz.leveland</groupId>
<artifactId>actutest</artifactId>
<version>0.0.1-SNAPSHOT</version>
<name>actutest</name>
<description>Actuator test</description>
<properties>
    <java.version>11</java.version>
    <spring-cloud.version>2021.0.3</spring-cloud.version>
</properties>
<dependencies>
    <dependency>
        <groupId>org.springframework.cloud</groupId>
        <artifactId>spring-cloud-config-server</artifactId>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-security</artifactId>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-actuator</artifactId>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-web</artifactId>
    </dependency>

    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-test</artifactId>
        <scope>test</scope>
    </dependency>
</dependencies>

application.properties配置

server:
  port: 8080

spring:
  application:
    name: CONFIG-SERVER
  cloud:
    config:
      server:
        git:
          uri: https://bitbucket.org/repo-name/actuator-test
          clone-on-start: true
          username: repouser
          password: xxxxxxxxxx
          default-label: master

encrypt:
  keyStore:
    location: classpath:/server2.jks
    password: letmein
    alias: mytestkey
    secret: letmein


management:
  endpoints:
    web:
      exposure:
        include: "health"

Spring应用类

@EnableConfigServer
@SpringBootApplication
public class ActutestApplication {

    public static void main(String[] args) {
        SpringApplication.run(ActutestApplication.class, args);
    }

}

Git仓库中的application.properties

spring.datasource.username=admin
spring.datasource.password={cipher}AQA50Mh4...

问题表现

访问任意Actuator端点(如/actuator/foo-bar)时,服务器返回完整Git配置源,示例响应:

{
  "name": "actuator",
  "profiles": [
    "foo-bar"
  ],
  "label": null,
  "version": "da200e047354e889e6503b10cbb9cbbc7e3dbb28",
  "state": null,
  "propertySources": [
    {
      "name": "https://bitbucket.org/repo-name/actuator-test/application.properties",
      "source": {
        "spring.datasource.username": "admin",
        "spring.datasource.password": "secret-password"
      }
    }
  ]
}
分析与解决方案

这不是安全漏洞,而是Spring Cloud Config Server的路由规则优先级导致的配置问题。

原因解释

Spring Cloud Config Server的核心路由规则会匹配/{name}/{profiles}/{label:.*}格式的请求,其中:

  • name对应配置文件的应用名称
  • profiles对应环境/配置文件后缀
  • label对应Git分支(可选)

当你访问/actuator/foo-bar时,Config Server的路由会把actuator识别为name,foo-bar识别为profiles,因此直接返回了对应名称和配置文件的Git配置内容,Actuator的404处理逻辑被Config Server的路由覆盖。

解决方法

有两种可靠的修复方式:

  1. 为Config Server设置独立路由前缀
    在application.properties中添加配置,让Config Server的路由与Actuator完全隔离:

    spring:
      cloud:
        config:
          server:
            servlet:
              path: /config
    

    此后Config Server的配置请求需通过/config/{name}/{profiles}访问,不再干扰/actuator开头的请求。

  2. 修改Actuator的基础路径
    调整Actuator的端点根路径,避免与Config Server的路由规则冲突:

    management:
      endpoints:
        web:
          base-path: /manage
          exposure:
            include: "health"
    

    此时Actuator的端点需通过/manage/health访问,不会被Config Server的路由匹配。

额外建议:为Config Server和Actuator添加Spring Security的角色认证控制,进一步保护敏感配置与监控端点的访问权限。

内容的提问来源于stack exchange,提问作者RomanDeveloper

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 22:50:35