VDB

GCVE-110-CLOUD-2019-0008

GCVE-110-CLOUD-2019-0008
Advisory Published
Vulnetix · Advisory published August 4, 2019
AWS offers a metadata service accessible to most EC2 Instances via a simple GET request to 169.254.169.254. If an instance has an SSRF vulnerability, attackers can access the metadata service & exfiltrate the credentials of an attached IAM role to gain privileged access to the relevant AWS environment.

Affected Products

VendorProductVersionsPlatforms
AWSCloud Services
AWSIAM
AWSEC2

Browse GCVE Records

74,868 records in the GCVE database · Updated July 26, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›