Paper Exploit Spring Boot Actuator 之 Spring Cloud Env 学习笔记
Spring Boot Actuator + Spring Cloud Vul Env for RCE by modifying spring.cloud.bootstrap.location
in https://www.veracode.com/blog/research/exploiting-spring-boot-actuators
master
: Spring Boot Actuator 1.5.22 + Spring Cloud Dalston.RELEASE2.2.1-cloud
: Spring Boot Actuator 2.2.1 + Spring Cloud Hoxton.RELEASE
src/main/resources/payload
remote jar payloadsrc/test/java/com/b1ngz/sec/SnakeYAMLTest.java
some tests