CVE-2022-30034

8.6
HIGHCVSS v3.1 Base Score
1.06%
LOW RiskEPSS (63rd percentile)

Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny service by shutting down Celery task nodes.

Published: 6/2/2022
Modified: 7/9/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

CVSS v2 Score

7.5

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

1.06%LOW Exploitation Risk
63rd percentile

This vulnerability has a 1.06% probability of being exploited in the next 30 days, ranking higher than 63% of all scored CVEs.

CWE Classification

Advertisement