Critical2024-07-13 · 4 min

Pre-Auth Full Read SSRF Leaking AWS Keys via Redirect Bypass

How I found a critical SSRF vulnerability that bypassed backend protections via an open redirect, exposing EC2 instance credentials — no authentication required.

SSRFAWSCloudCWE-918
Read writeup