Malicious Jamf Pro SSRF Targeting Cloud Metadata via imageUrl (via webserver)

PremiumReviewedSigma · Critical · v1
Category
webserver
Author
HuntRule
Published
2026-05-05
Updated
2026-08-28

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects requests to the Jamf Pro eduFeatureSettingsTest endpoint whose imageUrl parameter references the cloud instance metadata address 169.254.169.254. This is the full-read SSRF CVE-2021-39303 and CVE-2021-40809 aimed at stealing AWS instance credentials from the metadata service. Detecting it surfaces active theft of cloud IAM credentials through the vulnerable server.

Related detections9 linkedT1190 — drag to rearrange
Possible Jamf Pro SSRF Exploitation via eduFeatureSettingsTest imageUrl (via webserver)
Possible WebSphere Portal SSRF via Proxy Servlet targeting Cloud Metadata (CVE-2021-27748) (via webserver)
Possible SSRF to AWS Metadata via Workspace One UEM BlobHandler CVE-2021-22054
Possible SSRF via Gatsby _gatsby File Proxy Endpoint
Possible SSRF to Cloud Metadata via Nuxt _ipx Image Proxy
Possible Super SSRF via Jira Server nativemobile batch CVE-2022-26135
Suspicious SSRF Probe for Cloud Instance Metadata Service
Malicious Cloud Metadata Credential SSRF via HTTP (via proxy)
Possible Pre-Auth SSRF via VMware Workspace One UEM BlobHandler CVE-2021-22054
Malicious Jamf Pro SSRF Targeting Cloud Metadata via imageUrl (via webserver)
Pivot detection · T1190 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.