BlogsTemporalCVE Numbering Authority Program

CVE Numbering Authority Program

CVE Numbering Authority Program

1
posts
2023

Temporal has become a CVE Numbering Authority (CNA), enabling the company to assign CVE identifiers to vulnerabilities in its software. This initiative enhances transparency and security for users of Temporal Server and Temporal Cloud. A specific vulnerability (CVE-2023-3485) related to namespace protection in self-hosted Temporal Server was addressed in version 1.20.0, with a configuration option available in earlier versions to mitigate the risk.

2023

Temporal is now a CVE Numbering Authority (CNA)

7/20/2023

Temporal's new role as a CVE Numbering Authority (CNA) allows for the formal assignment of CVE identifiers to security vulnerabilities within its software. This post details a specific vulnerability, CVE-2023-3485, which affected self-hosted Temporal Server deployments due to a default configuration not enforcing namespace protections. The vulnerability was fixed in Temporal version 1.20.0, and a workaround using the `frontend.enableTokenNamespaceEnforcement` dynamic configuration option was made available in version 1.9.1 and later.