Command Injection Vulnerability in StackLift LocalStack by StackLift
CVE-2021-32090
9.8CRITICAL
What is CVE-2021-32090?
The dashboard component of StackLift LocalStack 0.12.6 is vulnerable to command injection, allowing attackers to inject arbitrary shell commands via the 'functionName' parameter. This flaw can lead to serious security breaches, as unauthorized commands can be executed in the system, potentially compromising sensitive data and system integrity. Users are advised to update to patched versions and review security practices to mitigate the risk associated with this vulnerability.
