πΌ [EC2.8] EC2 instances should use Instance Metadata Service Version 2 (IMDSv2)
- Contextual name: πΌ [EC2.8] EC2 instances should use Instance Metadata Service Version 2 (IMDSv2)
- ID:
/frameworks/aws-fsbp-v1.0.0/ec2/08
- Located in: πΌ Elastic Compute Cloud (EC2)
Descriptionβ
You use instance metadata to configure or manage the running instance. The IMDS
provides access to temporary, frequently rotated credentials. These credentials
remove the need to hard code or distribute sensitive credentials to instances
manually or programmatically. The IMDS is attached locally to every EC2 instance.
It runs on a special "link local" IP address of 169.254.169.254. This IP address
is only accessible by software that runs on the instance.
Version 2 of the IMDS adds new protections for the following types of vulnerabilities.
These vulnerabilities could be used to try to access the IMDS.
- Open website application firewalls
- Open reverse proxies
- Server-side request forgery (SSRF) vulnerabilities
- Open Layer 3 firewalls and network address translation (NAT)
Similarβ
- AWS Security Hub
- Internal
Similar Sections (Give Policies To)β
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|
Policies (1)β
Internal Rulesβ
Rule | Policies | Flags |
---|
βοΈ dec-x-b42fae78 | 1 | |