Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny service by shutting down Celery task nodes.
References
Link | Resource |
---|---|
http://githubcommherflower.com | Broken Link URL Repurposed |
https://github.com/mher/flower/issues/1217 | Exploit Issue Tracking |
https://tprynn.github.io/2022/05/26/flower-vulns.html | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2022-06-02 14:15
Updated : 2024-02-14 01:17
NVD link : CVE-2022-30034
Mitre link : CVE-2022-30034
CVE.ORG link : CVE-2022-30034
JSON object : View
Products Affected
flower_project
- flower
CWE
CWE-287
Improper Authentication