云虫漏洞情报

CVE-2026-82265 - Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read environment variables, bean configurations, and storage credentials via actuator endpoints, or modify log levels to suppress logging. - 漏洞详情

漏洞编号:CVE-2026-82265

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-82265

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-306

发布/更新时间:2026-08-28 / 2026-08-28

漏洞描述

Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read environment variables, bean configurations, and storage credentials via actuator endpoints, or modify log levels to suppress logging.

相关链接

相关漏洞

« 返回首页