A transit engagement identifies server-side request forgery that can reach cloud instance metadata endpoints. How should impact be framed without exploit steps?
Select an answer to reveal the explanation.
Short Explanation
Tricking the server into asking the cloud "who am I?" can spill temporary keys — that is a big deal. SSRF to metadata is a critical impact class; describe the risk class, not a recipe. It is not a missing favicon and it is not a hardware-console requirement.
Full Explanation
SSRF against cloud metadata services can expose instance identity documents or temporary credentials, enabling further cloud abuse. Testers should rate this as a high or critical impact class and recommend egress controls, metadata service hardening, and URL allowlisting — without providing exploitation recipes. Severity is far above cosmetic asset gaps. Framing stays on impact and remediation themes appropriate to CPTS similar-concept practice.