关键漏洞信息 标题 (Title) Halo 2.21.10 Exposure of Sensitive Information Due to Incompatible Policies 描述 (Description) In the Halo release version (currently the latest is 2.21.10), due to improper Spring actuator endpoint configurations that are also unnecessary for business operations, multiple sensitive endpoints (such as env, heapdump, logfile, etc.) are exposed, potentially resulting in the leakage of sensitive information. 来源 (Source) !Link User: WenGui (UID 82184) 提交时间 (Submission) 12/14/2025 02:38 PM (20 days ago) 审核时间 (Moderation) 12/27/2025 11:18 AM (13 days later) 状态 (Status) Accepted VulDB条目 (VulDB entry) 338519 [Halo up to 2.21.10 Configuration /actuator information disclosure] 分数 (Points) 18