Missing SSL Certificate Validation in LocalStack by LocalStack
CVE-2023-48054

7.4HIGH

Key Information:

Vendor

Localstack

Vendor
CVE Published:
16 November 2023

What is CVE-2023-48054?

The lack of SSL certificate validation in LocalStack version 2.3.2 exposes users to significant security risks, enabling attackers to intercept and monitor communications between the host and server. This vulnerability can lead to unauthorized data access and manipulation through potential man-in-the-middle attacks, posing threats to data confidentiality and integrity.

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.