LocalstackCVEs & Vulnerabilities
3 CVEs affecting Localstack products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
3 CVEs→ All vendors
Most Affected Products
localstack 3
CVE-2023-48054HIGH
Missing SSL certificate validation in localstack v2.3.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack.
16 Nov 2023
7.4
CVSS
CVE-2021-32091MEDIUM
A Cross-site scripting (XSS) vulnerability exists in StackLift LocalStack 0.12.6.
7 May 2021
6.1
CVSS
CVE-2021-32090CRITICAL
The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the functionName parameter.
7 May 2021
9.8
CVSS
← PrevPage 1 / 1Next →