PyPi: Localstack

CVE-2020-36518

Transitive

Safety vulnerability ID: 52461

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Mar 11, 2022 Updated at Apr 25, 2024
Scan your Python projects for vulnerabilities →

Advisory

Localstack 1.0.2 updates its MAVEN dependency 'jackson-databind' to v2.13.3 in the Docker image to include a security fix.

Affected package

localstack

Latest version: 3.4.0

LocalStack - A fully functional local Cloud stack

Affected versions

Fixed versions

Vulnerability changelog

What's Changed
* Moving zip utilities by giograno in https://github.com/localstack/localstack/pull/6490
* Changing ACM certificate fixture to handle regions as input parameters. by taras-kobernyk-localstack in https://github.com/localstack/localstack/pull/6479
* docs: change v1 banner by HarshCasper in https://github.com/localstack/localstack/pull/6483
* fix: print conserved docker logs if container is not running by HarshCasper in https://github.com/localstack/localstack/pull/6477
* fix ASF / botocore CBOR decoding by alexrashed in https://github.com/localstack/localstack/pull/6494
* Rework RegionBackend by viren-nadkarni in https://github.com/localstack/localstack/pull/6444
* Upgrade JAR files to resolve some recent security vulnerabilities by whummer in https://github.com/localstack/localstack/pull/6496
* Migrate to amazon_kclpy v2, remove obsolete custom patches by whummer in https://github.com/localstack/localstack/pull/6502
* fix podman compatibility for list_containers in container utils by hans-d in https://github.com/localstack/localstack/pull/6508
* Avoid shell expansion for zip utils by giograno in https://github.com/localstack/localstack/pull/6497
* Pin quart and werkzeug versions to fix recent changes in req ctx stack, URL Map by whummer in https://github.com/localstack/localstack/pull/6514
* Update README.md by bish0polis in https://github.com/localstack/localstack/pull/6510
* Update ASF APIs by localstack-bot in https://github.com/localstack/localstack/pull/6515
* fix Kinesis GetRecords on empty streams by alexrashed in https://github.com/localstack/localstack/pull/6516
* fix type hint compatibility in aws_stack.py by thrau in https://github.com/localstack/localstack/pull/6512
* Fix pytest log capture for integration tests by dfangl in https://github.com/localstack/localstack/pull/6519
* Utility to restart Docker containers by viren-nadkarni in https://github.com/localstack/localstack/pull/6489
* Fix Swagger spec imports of REST APIs with base paths by whummer in https://github.com/localstack/localstack/pull/6520
* bump moto-ext version to 3.1.13 by steffyP in https://github.com/localstack/localstack/pull/6524
* Minor: Skip upgrading JAR file if local version already matches by whummer in https://github.com/localstack/localstack/pull/6534
* fix EC2 ASF error serialization and botocore parsing by alexrashed in https://github.com/localstack/localstack/pull/6535
* added cloudwatch enable/disable actions by steffyP in https://github.com/localstack/localstack/pull/6491
* Add timestamp to SES retrospection messages by viren-nadkarni in https://github.com/localstack/localstack/pull/6526
* run tests with snapshot verify by default by steffyP in https://github.com/localstack/localstack/pull/6518

New Contributors
* taras-kobernyk-localstack made their first contribution in https://github.com/localstack/localstack/pull/6479
* hans-d made their first contribution in https://github.com/localstack/localstack/pull/6508
* bish0polis made their first contribution in https://github.com/localstack/localstack/pull/6510

**Full Changelog**: https://github.com/localstack/localstack/compare/v1.0.1...v1.0.2

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

HIGH 7.5

CVSS v3 Details

HIGH 7.5
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
NONE
Integrity Impact (I)
NONE
Availability Availability (A)
HIGH

CVSS v2 Details

MEDIUM 5.0
Access Vector (AV)
NETWORK
Access Complexity (AC)
LOW
Authentication (Au)
NONE
Confidentiality Impact (C)
NONE
Integrity Impact (I)
NONE
Availability Impact (A)
PARTIAL