First published: Fri May 07 2021(Updated: )
A Cross-site scripting (XSS) vulnerability exists in StackLift LocalStack 0.12.6.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
=0.12.6 | ||
pip/localstack | <=0.12.10 | |
Localstack Localstack | =0.12.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32091 is a Cross-site scripting (XSS) vulnerability in StackLift LocalStack 0.12.6.
The severity of CVE-2021-32091 is medium, with a severity value of 6.1.
CVE-2021-32091 affects StackLift LocalStack version 0.12.6.
Yes, you can find more information about CVE-2021-32091 at the following references: [reference 1](https://blog.sonarsource.com/hack-the-stack-with-localstack) and [reference 2](https://portswigger.net/daily-swig/localstack-zero-day-vulnerabilities-chained-to-achieve-remote-takeover-of-local-instances).
Yes, the Common Weakness Enumeration (CWE) associated with CVE-2021-32091 is CWE-79.