Default IMDSv1 Behavior
EC2 instances created without explicit metadata options default to allowing IMDSv1, which doesn't require session tokens.
SSRF could expose instance metadata and IAM role credentials, enabling privilege escalation, lateral movement, and unauthorized AWS API access.
EC2 instances created without explicit metadata options default to allowing IMDSv1, which doesn't require session tokens.
Sourcery automatically identifies server-side request forgery (ssrf) via imdsv1 metadata endpoint in aws ec2 and many other security issues in your codebase.