ec2-metadata

1 article
sort: new top best
clear filter
0 5/10

A researcher discovered an SSRF vulnerability in a crypto exchange platform's image loading endpoint that allowed reading local files via file:// protocol and extracting AWS EC2 metadata credentials from the 169.254.169.254 metadata service, ultimately achieving RCE and receiving a 4-digit bounty.

pratik yadav AWS EC2 Elastic Beanstalk brutelogic.com.br ENCIPHERS Abhinav mishra Narendra abhishek NotSoSecure
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 17 hours ago · details