CVE Numbering Authority Program
Temporal is now a CVE Numbering Authority (CNA)

Temporal is now a CVE Numbering Authority (CNA)

7/20/2023

What this post added

Temporal's new role as a CVE Numbering Authority (CNA) allows for the formal assignment of CVE identifiers to security vulnerabilities within its software. This post details a specific vulnerability, CVE-2023-3485, which affected self-hosted Temporal Server deployments due to a default configuration not enforcing namespace protections. The vulnerability was fixed in Temporal version 1.20.0, and a workaround using the `frontend.enableTokenNamespaceEnforcement` dynamic configuration option was made available in version 1.9.1 and later.

Read the original post ↗