CVE-2025-53602 Information

Description

Zipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator) a similar issue to CVE-2025-48927.

Reference

https://github.com/openzipkin/zipkin/commit/3c7605dfdfab2dd341cf0ea121a56cefcd580d9e https://github.com/openzipkin/zipkin/pull/3804 https://zipkin.io/

CNNVD-202507-504 (Published: 2025-07-04)

Share on: