diff --git a/security-misconfiguration/springboot-detect.yaml b/security-misconfiguration/springboot-detect.yaml index 43f4c3db2e..4b652add89 100644 --- a/security-misconfiguration/springboot-detect.yaml +++ b/security-misconfiguration/springboot-detect.yaml @@ -11,7 +11,6 @@ requests: - "{{BaseURL}}/trace" - "{{BaseURL}}/loggers" - "{{BaseURL}}/autoconfig" - - "{{BaseURL}}/heapdump" - "{{BaseURL}}/threaddump" - "{{BaseURL}}/env" - "{{BaseURL}}/management" @@ -20,29 +19,29 @@ requests: - "{{BaseURL}}/mappings" - "{{BaseURL}}/auditevents" - "{{BaseURL}}/beans" - - "{{BaseURL}}/jolokia" - "{{BaseURL}}/cloudfoundryapplication" - - "{{BaseURL}}/jolokia" - - "{{BaseURL}}/hystrix.stream" - "{{BaseURL}}/actuator" - "{{BaseURL}}/actuator/auditevents" - "{{BaseURL}}/actuator/beans" + - "{{BaseURL}}/actuator/health" - "{{BaseURL}}/actuator/conditions" - "{{BaseURL}}/actuator/configprops" - "{{BaseURL}}/actuator/env" - - "{{BaseURL}}/actuator/heapdump" + - "{{BaseURL}}/actuator/dump" - "{{BaseURL}}/actuator/threaddump" - - "{{BaseURL}}/actuator/jolokia" - - "{{BaseURL}}/actuator/hystrix.stream" - "{{BaseURL}}/actuator/flyway" - "{{BaseURL}}/actuator/integrationgraph" - "{{BaseURL}}//actuator/management" matchers: - - type: word - words: + - type: regex + part: body + regex: - 'method' - 'spring' - - '' + - 'TYPE' + - 'system' + - 'database' + - 'cron' condition: or - type: status status: @@ -50,6 +49,6 @@ requests: - type: word words: - 'application/json' - - 'attachment' + - 'hprof' condition: or part: header