Server-Side Request Forgery (AWS)

Severity: High

Invicti detected a Server-Side Request Forgery based on pattern matching and confirmed the vulnerability using specific AWS meta-data API requests.


Server-Side Request Forgery allows an attacker to make local and/or remote network requests while masquerading as the target server.

Having an AWS meta-data API endpoint that is accessible through SSRF MAY lead to total compromise of the virtual computer and other AWS resources that are accessible by the compromised account.

  • Where possible, do not use users' input for URLs.
  • If you definitely need dynamic URLs, use whitelisting. Make a list of valid, accepted URLs and do not accept other URLs.
  • Ensure that you only accept URLs those are located on the trusted domains.

Build your resistance to threats. And save hundreds of hours each month.

Get a demo See how it works