graph-explorer icon indicating copy to clipboard operation
graph-explorer copied to clipboard

[Feature Request] Ensure graph-explorer supports IMDSv2-only when deployed to an EC2 instance

Open triggan opened this issue 1 year ago • 1 comments

Community Note

  • Please use a 👍 reaction to provide a +1/vote. This helps the community and maintainers prioritize this request.
  • If you are interested in working on this issue or have submitted a pull request, please leave a comment.

Graph Explorer Version (and Graph Database and Version used if applicable)

Is your feature request related to a problem? Please describe. A clear and concise description of what the problem is. Ex. I'm frustrated when [...]

AWS launched support for a more secure instance metadata store (IMDS) back in 2019. Many have asked (in other forums) if graph-explorer supports using only IMDSv2 (disabling IMDSv1) for security purposes. Submitting this issue as a "to do" to ensure that graph-explorer can be used in these situations.

IMDSv2 launch blog: https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service/

triggan avatar Jun 15 '23 13:06 triggan