Web Hack List

Collected research

Chaining Exposed Actuators and H2 Database Aliases in Spring Boot 2

Remote Code Execution in Three Acts: Chaining Exposed Actuators and H2 Database Aliases in Spring Boot 2

An exposed Spring Boot 2 actuator env endpoint lets an attacker set the HikariCP connection test query, which the pool runs as SQL on the next database connection. Against an H2 database that query can CREATE ALIAS a Java function and call it, giving remote code execution, with CONCAT and HEXTORAW string tricks to evade WAF filters.

Record

Document
Remote Code Execution in Three Acts: Chaining Exposed Actuators and H2 Database Aliases in Spring Boot 2
Published by
spaceraccoon.dev
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of spaceraccoon.dev, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .