SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-16925

Flower 0.9.3 has XSS via the name parameter in an @app.task call.

MEDIUM 6.1EPSS 0.82%

Does this matter?

Lower severity and a low EPSS score (0.82%). Track it; it rarely justifies an emergency change on its own.

Description

Flower 0.9.3 has XSS via the name parameter in an @app.task call. NOTE: The project author stated that he doesn't think this is a valid vulnerability. Worker name and task name aren’t user facing configuration options. They are internal backend config options and person having rights to change them already has full access

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.82% probability · 55th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
flower project/flower
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.