AWS Systems Manager Agent SSRF Vulnerability Requires Immediate Update
AWS Systems Manager Agent versions below 3.3.4851.0 have a server-side request forgery flaw in Session Manager port forwarding. Authenticated users with port-forwarding permissions could bypass security controls to access link-local endpoints and steal temporary IAM credentials. Action required: update SSM Agent immediately on all affected managed nodes to patch this important vulnerability.
source: [aws/security-bulletin]