logoalt Hacker News

chc4yesterday at 8:20 PM1 replyview on HN

SSRF is not just a DoS.


Replies

CodesInChaosyesterday at 10:09 PM

To have a significant impact SSRF needs to be combined with a second worse vulnerability: An endpoint that trusts unauthenticated requests just because they come from within the local network. Sadly several popular clouds have such a vulnerability out of the box (metadata endpoint).

show 1 reply