Fortify scan reports this property in spring-boot application.properties as high issue as it assumes password in plain text. Below code reads the password from environment variable.I have environment variables(DB_PASSWORD) in kubernetes cluster.so I need to have this property in spring-boot application.
can anyone provide any other alternatives?
spring.datasource.password=${DB_PASSWORD:}