VDB
GCVE-110-CLOUD-2019-0008
GCVE-110-CLOUD-2019-0008
Advisory Published
AWS offers a metadata service accessible to most EC2 Instances via a simple GET request to 169.254.169.254.
If an instance has an SSRF vulnerability, attackers can access the metadata service & exfiltrate the credentials
of an attached IAM role to gain privileged access to the relevant AWS environment.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| AWS | Cloud Services | — | — |
| AWS | IAM | — | — |
| AWS | EC2 | — | — |
References
Browse GCVE Records
74,868 records in the GCVE database · Updated July 26, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.