Executive brief
The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the functionName parameter.
Affected products
- PyPI localstack
Junglewise Threat Intelligence
CVE-2021-32090 · Severity: low · CVSS 3.1 · Published 2021-05-07
Technologies: localstack (PyPI). Vendors: PyPI.
The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the functionName parameter.