Description
Allowing IMDSv1 can make instance metadata or temporary credentials easier to reach through some SSRF vulnerabilities. IMDSv2 requires a session token and provides additional protection.
Potential impact
Combined with an application vulnerability, this can expose metadata or instance-role credentials.
Remediation
Set MetadataOptions.HttpTokens to required when the metadata service is needed, and verify application compatibility. If the service is unnecessary, its endpoint can be disabled.
Examples
When explicit options are absent, actual behavior depends on AMI and account defaults. These examples require IMDSv2 on an instance and launch template; choose AmiId and the hop limit for the environment.
Before
yaml
AWSTemplateFormatVersion: '2010-09-09'
Description: Metadata option comparison
Resources:
MyEC2Instance:
Type: AWS::EC2::Instance
Properties:
ImageId: !Ref AmiId
InstanceType: t3.micro
MyLaunchTemplate:
Type: AWS::EC2::LaunchTemplate
Properties:
LaunchTemplateName: MySecureLaunchTemplate
LaunchTemplateData:
ImageId: !Ref AmiId
InstanceType: t3.micro
After
yaml
AWSTemplateFormatVersion: '2010-09-09'
Description: Metadata option comparison
Resources:
MyEC2Instance:
Type: AWS::EC2::Instance
Properties:
ImageId: !Ref AmiId
InstanceType: t3.micro
MetadataOptions:
HttpEndpoint: enabled
HttpTokens: required
HttpPutResponseHopLimit: 2
HttpProtocolIpv6: disabled
MyLaunchTemplate:
Type: AWS::EC2::LaunchTemplate
Properties:
LaunchTemplateName: MySecureLaunchTemplate
LaunchTemplateData:
ImageId: !Ref AmiId
InstanceType: t3.micro
MetadataOptions:
HttpEndpoint: enabled
HttpTokens: required
HttpPutResponseHopLimit: 2
HttpProtocolIpv6: disabled