Server-side request forgery (SSRF) TL;DR: App makes a request the attacker controls — pivot into internal services and cloud metadata. Stub — to be filled in. What it is TODO Preconditions / where it applies TODO Technique TODO Detection and defence TODO References https://portswigger.net/web-security/ssrf