GHSA-94ww-22rx-493x

Suggest an improvement
Source
https://github.com/advisories/GHSA-94ww-22rx-493x
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-94ww-22rx-493x/GHSA-94ww-22rx-493x.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-94ww-22rx-493x
Withdrawn
2021-02-24T19:46:35Z
Published
2021-02-24T19:46:35Z
Modified
2024-12-01T05:32:18Z
Summary
Cross-Site Scripting
Details

Flower, before 0.9.2, has a XSS on tasks page because data is not properly escaped.

Database specific
{
    "cwe_ids": [],
    "github_reviewed": true,
    "github_reviewed_at": "2019-06-05T13:52:45Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

PyPI / flower

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.9.2

Affected versions

0.*
0.1.0
0.2.0
0.3.0
0.3.1
0.4.0
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-94ww-22rx-493x/GHSA-94ww-22rx-493x.json"