Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny service by shutting down Celery task nodes.
References
Link | Resource |
---|---|
https://tprynn.github.io/2022/05/26/flower-vulns.html | Exploit Third Party Advisory |
http://githubcommherflower.com | Broken Link |
https://github.com/mher/flower/issues/1217 | Third Party Advisory |
Configurations
Information
Published : 2022-06-02 07:15
Updated : 2022-10-26 15:48
NVD link : CVE-2022-30034
Mitre link : CVE-2022-30034
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
flower_project
- flower