aws-sdk-java-v2-secrets-manager
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
AnomalyAnomalyreferences/spring-boot-integration.md
LOWAnomalyLOW
references/spring-boot-integration.md
No clear malicious or supply-chain attack behavior is present. The code implements expected AWS Secrets Manager access and credential use. The main security issue is that caller-controlled endpoint values receive secret-derived HTTP headers, enabling potential credential disclosure and SSRF; restrict endpoints to an HTTPS allowlist and avoid forwarding credentials to untrusted destinations. CSRF configuration, incomplete property-source registration, and sample-code compilation inconsistencies also require review.
Confidence: 97%Severity: 55%
Audit Metadata