Temporal

Temporal

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 10.04.2026 21:16:28
  • Zuletzt bearbeitet 13.04.2026 15:02:06

The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper and Authorizer are configured, unary RPCs enforce authentication and authorization, but the streaming AdminService/StreamWorkflow...

  • EPSS 0.04%
  • Veröffentlicht 01.04.2026 17:49:15
  • Zuletzt bearbeitet 03.04.2026 16:10:52

A writer role user in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster. Exploitation requires the attacker to know or guess specific victim workflow ID(s) and, for sign...

Medienbericht
  • EPSS 0.03%
  • Veröffentlicht 30.12.2025 20:17:47
  • Zuletzt bearbeitet 15.04.2026 00:35:42

When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates for the embedded StartWorkflowExecutionRequest using its Namespace field rather than the outer, authorized ExecuteMultiOperationR...

  • EPSS 0.03%
  • Veröffentlicht 30.12.2025 20:16:20
  • Zuletzt bearbeitet 15.04.2026 00:35:42

When system.enableCrossNamespaceCommands is enabled (on by default), the Temporal server permits certain workflow task commands (e.g. StartChildWorkflowExecution, SignalExternalWorkflowExecution, RequestCancelExternalWorkflowExecution) to target a di...

  • EPSS 0.07%
  • Veröffentlicht 03.04.2024 22:15:07
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Denial of Service in Temporal Server prior to version 1.20.5, 1.21.6, and 1.22.7 allows an authenticated user who has permissions to interact with workflows and has crafted an invalid UTF-8 string for submission to potentially cause a crashloop. If l...

  • EPSS 0.02%
  • Veröffentlicht 30.06.2023 18:15:10
  • Zuletzt bearbeitet 21.11.2024 08:17:22

Insecure defaults in open-source Temporal Server before version 1.20 on all platforms allows an attacker to craft a task token with access to a namespace other than the one specified in the request. Creation of this task token must be done outside of...