Six Common API Parameters Exploited in 69,000 SSRF Probes Targeting Cloud Metadata
In March 2025, a single threat actor conducted over 69,000 probes targeting cloud servers by exploiting six common URL-accepting API parameters — url, dest, file, redirect, target, and uri — all aimed at the AWS Instance Metadata Service address 169.254.169.254. F5 Labs documented the campaign, highlighting that these parameter types exist in virtually every production API, including webhook callbacks, import-from-URL endpoints, and OAuth validators. The severity of such Server-Side Request Forgery (SSRF) attacks depends heavily on whether a cloud instance runs IMDSv1 or IMDSv2, as IMDSv1 allows unauthenticated credential theft via a single GET request. AWS disabled IMDSv1 by default for new instances in November 2023, but existing instances remain vulnerable unless explicitly migrated. Real-world cases such as CVE-2021-21311 and the ProxyLogon exploit chain (CVE-2021-26855) demonstrate how SSRF vulnerabilities can escalate from data exposure to full credential theft or remote code execution.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in