Closed
Description
Ref: https://tprynn.github.io/2022/05/26/flower-vulns.html
- Flower is unauthenticated by default and lacks CSRF protections
- Flower's OAuth support is vulnerable to a bypass allowing anyone to authenticate regardless of the
auth_regexrestriction
Due to a lack of response from the maintainer, these issues were publicly disclosed on 26 May 2022 along with a PR (#1216)