First published: Thu Nov 16 2023(Updated: )
Missing SSL certificate validation in localstack allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/localstack | <=3.0.0 | |
Localstack Localstack | =2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48054 is a vulnerability that allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack due to missing SSL certificate validation in localstack v2.3.2.
CVE-2023-48054 has a severity rating of high (7.4 out of 10).
The affected software is localstack v2.3.2.
An attacker can exploit CVE-2023-48054 by performing a man-in-the-middle attack to eavesdrop on the communication between the host and server.
Yes, to fix CVE-2023-48054, update localstack to a version that includes SSL certificate validation.