StackRadar

CVE-2022-30034

High

Advisory

Published 2 Jun 2022In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
8.6
base score, highest
EPSS
0.011
63rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4
of 17,781 indexed, latest versions
Container images
4
deployed by those charts
Fix available
1 of 1
affected package

Flower OAuth authentication bypass

Carried by container images the latest versions of 4 of 17,781 indexed charts deploy, on 4 images.

Affected packageAffected versionsFixed inImages
flowerpypi0.9.2, 0.9.7, 1.0.01.2.04
OSV records
GHSA-q4qm-xhf9-4p8f
Also known as
PYSEC-2022-42973

Charts affected

4 by stars
ChartLatestAffected imagesRadar Score
open-notificatiesopen-zaak0.7.01 of 4See more

open-notificaties open-zaak 0.7.0

1 of the 4 container images this version deploys carry CVE-2022-30034.

Container imageDigestPackageFixed in
openzaak/open-notificaties:1.3.02e65313b9b10
flower@1.0.0
1.2.0

Open the chart page →

2,850
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2022-30034.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
flower@0.9.7
1.2.0

Open the chart page →

22,891
supersetcloudnativeapp1.1.61 of 1See more

superset cloudnativeapp 1.1.6

1 of the 1 container images this version deploys carry CVE-2022-30034.

Container imageDigestPackageFixed in
amancevice/superset:0.28.1c8c04bfe3d66
flower@0.9.2
1.2.0

Open the chart page →

5,060
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2022-30034.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
flower@0.9.7
1.2.0

Open the chart page →

16,417

Container images carrying it

4 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
amancevice/superset:0.28.1c8c04bfe3d66
flower@0.9.2
1.2.0
1
gethue/hue:4.11.011b649636e68
flower@0.9.7
1.2.0
1
gethue/hue:4.10.05702b2c37ff9
flower@0.9.7
1.2.0
1
openzaak/open-notificaties:1.3.02e65313b9b10
flower@1.0.0
1.2.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.