PT-2025-28022 · Unknown+1 · Spring-Boot-Actuator+1

Published

2025-07-04

·

Updated

2025-07-05

·

CVE-2025-53602

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Zipkin versions prior to 3.5.2
Description: The issue is related to the exposure of heap dump information through the "/heapdump" endpoint, which is associated with the use of Spring Boot Actuator. This endpoint is similar to a previously identified issue.
Recommendations: For versions prior to 3.5.2, update to version 3.5.2 or later to resolve the issue. As a temporary workaround, consider disabling the "/heapdump" endpoint until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-53602
GHSA-794X-8X6X-QPFC

Affected Products

Spring-Boot-Actuator
Zipkin