Version endpoint
User header is logged by Log4j.
Log4ShellSpring Boot vulnerable surface for Log4Shell, XXE, deserialization and disclosure flows.
User header is logged by Log4j.
Log4ShellParses XML with unsafe entity settings.
XXEAccepts serialized object bytes.
Insecure DeserializationReads arbitrary paths from query string.
Path TraversalTry: /api/version, /api/xml, /api/files?path=/app, /api/env, /health