Home
MEDIUM: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NDefault status
unknown
Any version
affected
Description
Zipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-2025-48927.
Problem types
CWE-1188 Initialization of a Resource with an Insecure Default
Product status
Any version
References
github.com/...ommit/3c7605dfdfab2dd341cf0ea121a56cefcd580d9e
github.com/openzipkin/zipkin/pull/3804