Spring Boot Admins integrated notifier support allows arbitrary code execution
Package
de.codecentric.boot.admin.server.notify
(Spring Boot Admin Server - Notifier)
Affected versions
< 2.6.10
< 2.7.8, 2.7.11
< 3.0.0-M6
Patched versions
2.6.10
2.7.8, 2.7.9, 2.7.10, > 2.7.12
3.0.0-M6
Impact
All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are possibly affected.
Patches
In the most recent releases of Spring Boot Admin 2.6.10 and 2.7.8 the issue is fixed by implementing
SimpleExecutionContext
of SpEL. This prevents the arbitrary code execution (i.e. SpEL injection).Workarounds
/env
actuator endpoint