Severity: Critical
Invicti detected a Server-Side Request Forgery based on pattern matching and confirmed the vulnerability using specific Oracle Cloud meta-data API requests.
Server-Side Request Forgery allows an attacker to make local and/or remote network requests while masquerading as the target server.
Having an Oracle Cloud meta-data API endpoint that is accessible through SSRF MAY lead to total compromise of the virtual computer and other Oracle Cloud resources that are accessible by the compromised account.