Explorar o código

【5037】修复信息科反馈系统安全漏洞攻击事件

ZhuJiaHao hai 7 meses
pai
achega
9ba7816ea7

+ 87 - 8
ibps-basic-root/modules/basic-response/src/main/resources/config/application-common.yml

@@ -38,34 +38,110 @@ app:
       weight: 10
     - host: 192.168.3.240
       weight: 10
+## 端点暴露问题,会导致用户的安全扫描报警,注释掉,勿删,仅供参考
+#management:
+#  endpoints:
+#    shutdown:
+#      enabled: false
+#      sensitive: false
+#    web:
+#      base-path: /
+#      exposure:
+#        include: '*'
+#        exclude: beans
+#  metrics:
+#    tags:
+#      application: ${spring.application.name}
+#    export:
+#      prometheus:
+#        enabled: true
+#        step: 1ms
+#        descriptions: true
+#  endpoint:
+#    health:
+#      enabled: true
+#      show-details: always
+#    env:
+#      enabled: true
+#    prometheus:
+#      enabled: true
+#    mappings:
+#      enabled: false
+#  health:
+#    mail:
+#      enabled: false
+#    redis:
+#      enabled: false
+#    rabbit:
+#      enabled: false
+#    mongo:
+#      enabled: false
+
+
+## 新增内容,关闭端点暴露
 management:
   endpoints:
+    enabled-by-default: false
     shutdown:
       enabled: false
       sensitive: false
     web:
       base-path: /
       exposure:
-        include: '*'
-        exclude: beans
+        include: ""
+        exclude: "*"
   metrics:
     tags:
       application: ${spring.application.name}
     export:
       prometheus:
-        enabled: true
+        enabled: false
         step: 1ms
         descriptions: true
   endpoint:
+    # 显式禁用所有端点
     health:
-      enabled: true
-      show-details: always
+      enabled: false
+    info:
+      enabled: false
     env:
-      enabled: true
-    prometheus:
-      enabled: true
+      enabled: false
+    heapdump:
+      enabled: false
+    configprops:
+      enabled: false
+    beans:
+      enabled: false
     mappings:
       enabled: false
+    trace:
+      enabled: false
+    dump:
+      enabled: false
+    autoconfig:
+      enabled: false
+    metrics:
+      enabled: false
+    loggers:
+      enabled: false
+    auditevents:
+      enabled: false
+    httptrace:
+      enabled: false
+    threaddump:
+      enabled: false
+    conditions:
+      enabled: false
+    flyway:
+      enabled: false
+    liquibase:
+      enabled: false
+    scheduledtasks:
+      enabled: false
+    prometheus:
+      enabled: false
+    shutdown:
+      enabled: false
   health:
     mail:
       enabled: false
@@ -75,6 +151,9 @@ management:
       enabled: false
     mongo:
       enabled: false
+
+
+
 logging:
   config: classpath:config/log4j2.yml
 ##---------邮箱配置---------