Description
IMDSv1 accesses instance metadata without a session token and can be abused through attacks such as SSRF. When the metadata endpoint is enabled, http_tokens = "optional" also permits IMDSv1. Omitted options are affected by account and AMI settings, so verify the effective values.
Potential impact
- A vulnerable application can expose metadata or temporary role credentials.
- Stolen credentials can be abused within the instance profile’s permissions.
Remediation
Check SDK, bootstrap-script, and container compatibility, then set http_tokens = "required" for metadata access that is needed. Consider disabling the endpoint if metadata is unnecessary. Also fix SSRF vulnerabilities and minimize role permissions; IMDSv2 is an additional protection.
Examples
These excerpts compare metadata options. Replace the AMI with one valid in the target Region, and review launch-template and Auto Scaling settings as well.
Before
resource "aws_instance" "example" {
ami = "ami-12345678"
instance_type = "t2.micro"
metadata_options {
http_tokens = "optional"
}
}
After
resource "aws_instance" "example" {
ami = "ami-12345678"
instance_type = "t2.micro"
metadata_options {
http_endpoint = "enabled"
http_tokens = "required"
}
}
The first setting allows IMDSv1 when the endpoint is enabled. The second enables the endpoint and requires an IMDSv2 token. This change alone does not prevent every SSRF attack.