Cloud-Metadata SSRF: From One URL to Full Account Takeover
On a cloud host, a single server-side request forgery aimed at the link-local metadata endpoint can hand an attacker temporary cloud credentials. Here is how the IMDSv1, GCP and Azure variants work, and how to shut the door.