logo

CVE-2022-30034 flower

Package

Manager: pip
Name: flower
Vulnerable Version: <=1.0.0

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N

EPSS: 0.0014 pctl0.3466

Details

Flower OAuth authentication bypass All versions of Flower, a web UI for the Celery Python RPC framework, as of 05-02-2022 are vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny service by shutting down Celery task nodes. A fix was released in version 1.2.0.

Metadata

Created: 2022-06-03T00:01:07Z
Modified: 2024-09-20T20:09:21Z
Source: MANUAL
CWE IDs: ["CWE-287"]
Alternative ID: GHSA-q4qm-xhf9-4p8f
Finding: F039
Auto approve: 1