logo

CORS-anywhere: The Dangers of Misconfigured Third-Party Software

ID: be58445a-8d5d-5787-b9fc-19f8eb4579eb

STIX ID: report--be58445a-8d5d-5787-b9fc-19f8eb4579eb

Feed Name: CertiK Blog

Threat Score
70/100

Date Published: 2020-06-10

Date Updated: 2026-06-11

...
...

CertiK's pentesting team discovered a critical SSRF vulnerability in a misconfigured CORS-anywhere proxy used by a Cosmos blockchain explorer; the proxy allowed server-side requests to AWS EC2 instance metadata (IMDSv1 and IMDSv2), enabling retrieval of IAM role credentials and potential full access to S3 buckets and CloudWatch Logs. The report explains the vulnerability, demonstrates exploitation techniques for both IMDS versions, documents finding ~100 exposed EC2 instances on the internet, and recommends mitigations including restricting CORS origins, deploying reverse proxies, using WebSockets, and securing or disabling the instance metadata service.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.