EC2 Metadata Insecure
The EC2 Metadata Service (IMDS) lacks authentication, posing a risk of unauthorised access to sensitive services. Adversaries could extract valuable information, such as service tokens, from this endpoint, potentially gaining unauthorised access to other AWS services.
Remediation
Enable token requirement for IMDS. See https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/instance#metadata-options
Metadata
- Severity: high
- Slug: ec2-metadata-insecure
CWEs
- 284: Improper Access Control
OWASP
- A05:2021: Security Misconfiguration