CVE-2022-30034

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-30034
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-30034.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-30034
Aliases
Related
Published
2022-06-02T14:15:51Z
Modified
2024-10-12T09:31:32.372315Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H CVSS Calculator
Summary
[none]
Details

Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny service by shutting down Celery task nodes.

References

Affected packages

Git / github.com/mher/flower

Affected ranges

Type
GIT
Repo
https://github.com/mher/flower
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.2
v0.3
v0.4
v0.5
v0.5.1
v0.5.2
v0.6
v0.7
v0.8

v1.*

v1.0.0
v1.1.0