id: springboot-gateway info: name: Detect Spring Gateway Actuator author: wdahlenb severity: medium description: Sensitive environment variables may not be masked reference: - https://wya.pl/2021/12/20/bring-your-own-ssrf-the-gateway-actuator/ metadata: max-request: 2 tags: springboot,exposure,misconfig http: - method: GET path: - "{{BaseURL}}/gateway/routes" - "{{BaseURL}}/actuator/gateway/routes" stop-at-first-match: true matchers-condition: and matchers: - type: word part: body words: - "predicate" - "route_id" condition: and - type: word part: header words: - "application/json" - type: status status: - 200 # digest: 4b0a00483046022100a3565c1587f6f0d896a24687d141608114636bbba8b7532126b197ee3e3a0567022100ce2507bf93a6d1d73d6263e075c146ab7cac9441ad10f88abafc7cff8b8497ed:922c64590222798bb761d5b6d8e72950