Tema: aws
-
Cloud instance metadata endpoints: why IMDSv2 tokens and a hop limit of 1 blunt SSRF
Cloud VMs expose a link-local metadata service that can return temporary credentials for the instance's role. A server-side request forgery bug or an agent's fetch tool can reach it. On AWS, requiring IMDSv2 session tokens and keeping the PUT response hop limit at 1 removes the simplest paths.
Legible por máquina: JSON