Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny service by shutting down Celery task nodes.
References
Link | Resource |
---|---|
http://githubcommherflower.com | Broken Link URL Repurposed |
https://github.com/mher/flower/issues/1217 | Exploit Issue Tracking |
https://tprynn.github.io/2022/05/26/flower-vulns.html | Exploit Third Party Advisory |
Configurations
History
14 Feb 2024, 01:17
Type | Values Removed | Values Added |
---|---|---|
References | () http://githubcommherflower.com - Broken Link, URL Repurposed |
13 Feb 2024, 17:21
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/mher/flower/issues/1217 - Exploit, Issue Tracking |
26 Oct 2022, 22:48
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://github.com/mher/flower/issues/1217 - Third Party Advisory |
16 Aug 2022, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
10 Jun 2022, 17:19
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-287 | |
CPE | cpe:2.3:a:flower_project:flower:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 8.6 |
References | (MISC) https://tprynn.github.io/2022/05/26/flower-vulns.html - Exploit, Third Party Advisory | |
References | (MISC) http://githubcommherflower.com - Broken Link |
02 Jun 2022, 14:53
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-06-02 14:15
Updated : 2024-02-14 01:17
NVD link : CVE-2022-30034
Mitre link : CVE-2022-30034
CVE.ORG link : CVE-2022-30034
JSON object : View
Products Affected
flower_project
- flower
CWE
CWE-287
Improper Authentication