
Temporal is now a CVE Numbering Authority (CNA)
7/20/2023
Temporal's new role as a CVE Numbering Authority (CNA) allows for the formal assignment of CVE identifiers to security vulnerabilities within its software. This post details a specific vulnerability, CVE-2023-3485, which affected self-hosted Temporal Server deployments due to a default configuration not enforcing namespace protections. The vulnerability was fixed in Temporal version 1.20.0, and a workaround using the `frontend.enableTokenNamespaceEnforcement` dynamic configuration option was made available in version 1.9.1 and later.