SCA: security update for go.temporal.io/server (GHSA-gm2g-2xr9-pxxj)

low Tenable Cloud Security Plugin ID 415190

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Insecure defaults in open-source Temporal Server before version 1.20 on all platforms allows an attacker
to craft a task token with access to a namespace other than the one specified in the request. Creation of
this task token must be done outside of the normal Temporal server flow. It requires the namespace UUID
and information from the workflow history for the target namespace. Under these conditions, it is possible
to interfere with pending tasks in other namespaces, such as marking a task failed or completed. If a task
is targeted for completion by the attacker, the targeted namespace must also be using the same data
converter configuration as the initial, valid, namespace for the task completion payload to be decoded by
workers in the target namespace. (CVE-2023-3485)

See Also

https://github.com/advisories/GHSA-gm2g-2xr9-pxxj

Plugin Details

Severity: Low

ID: 415190

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 7.51

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Low

Base Score: 2.4

Temporal Score: 1.8

Vector: CVSS2#AV:L/AC:H/Au:S/C:N/I:P/A:P

CVSS Score Source: CVE-2023-3485

CVSS v3

Risk Factor: Low

Base Score: 3.6

Temporal Score: 3.2

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/30/2023

Vulnerability Publication Date: 6/30/2023

Reference Information

CVE: CVE-2023-3485