Cloud Metadata Access
- Category
- Server-Side Request Forgery
- Confidence
- 90% confidence
- Finding
Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.
- Content
python if parsed.scheme.lower() not in ("http", "https"): raise ValueError(f"无效的 URL 协议 '{parsed.scheme}',仅允许 'http://' 与 'https://'。") hostname = (parsed.hostname or "").lower() unsafe_hosts = ("localhost", "127.0.0.1", "0.0.0.0", "169.254.169.254") if hostname in unsafe_hosts or hostname.startswith("192.168.") or hostname.startswith("10."): raise ValueError(f"禁止指向回环、私网子网或云元数据端点({hostname})。") return raw_url.strip()
