Merge pull request #7942 from kazet/aws-other-cloud-provider

AWS metadata description informs that it could be other cloud provider
patch-1
pussycat0x 2023-08-16 23:12:58 +05:30 committed by GitHub
commit 1ad073713d
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 1 additions and 1 deletions

View File

@ -12,7 +12,7 @@ info:
name: Amazon AWS Metadata Service Check
author: sullo,DhiyaneshDk
severity: critical
description: The AWS host is configured as a proxy which allows access to the metadata service. This could allow significant access to the host/infrastructure.
description: The host is configured as a proxy which allows access to the metadata provided by a cloud provider such as AWS or OVH. This could allow significant access to the host/infrastructure.
reference:
- https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html
- https://blog.projectdiscovery.io/abusing-reverse-proxies-metadata/