Home / Vulnerability Database / Config files : DevTools enabled
Config files

Config files : DevTools enabled

Classification

Overview

The Spring Boot application is configured in developer mode.

The application uses a DevTools instruments that can make the development proccess more comfortable. An attacker can exploit this functionality if DevTools explicity used in a production environment.

In the official Spring Boot documentation stated: “Enabling spring-boot-devtools on a remote application is a security risk. You should never enable support on a production deployment.”

MEDIUM

DerScanner Severity Score

Do you want to fix Config files : DevTools enabled in your application?

See also

Config files

Config files : Text4Shell Vulnerability

Config files

Config files : Incorrect directory deletion

Config files

Config files : Code injection