CVE-2019-16925: XSS
DISPUTED Flower 0.9.3 has XSS via the name parameter in an @app.task call. NOTE: The project author stated that he doesn't think this is a valid vulnerability. Worker name and task name aren’t user facing configuration options. They are internal backend config options and person having rights to change them already has full access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-16925?
CVE-2019-16925 is considered a disputed XSS vulnerability in Flower version 0.9.3.
How do I fix CVE-2019-16925?
To address CVE-2019-16925, consider upgrading to a later version of Flower that does not include the vulnerability.
What are the affected versions for CVE-2019-16925?
CVE-2019-16925 affects Flower version 0.9.3.
Is CVE-2019-16925 a valid vulnerability?
The project author disputes the validity of CVE-2019-16925, stating the parameters are not user-facing.
What type of vulnerability is CVE-2019-16925?
CVE-2019-16925 is classified as an XSS (Cross-Site Scripting) vulnerability.