Логотип exploitDog
bind:CVE-2025-1243
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-1243

Количество 2

Количество 2

nvd логотип

CVE-2025-1243

12 месяцев назад

The Temporal api-go library prior to version 1.44.1 did not send `update response` information to Data Converter when the proxy package within the api-go module was used in a gRPC proxy prior to transmission. This resulted in information contained within the `update response` field not having Data Converter transformations (e.g. encryption) applied. This is an issue only when using the UpdateWorkflowExecution APIs (released on 13th January 2025) with a proxy leveraging the api-go library before version 1.44.1. Other data fields were correctly sent to Data Converter. This issue does not impact the Data Converter server. Data was encrypted in transit. Temporal Cloud services are not impacted.

EPSS: Низкий
github логотип

GHSA-q9w6-cwj4-gf4p

12 месяцев назад

Unencrypted transmission in Temporal api-go library

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-1243

The Temporal api-go library prior to version 1.44.1 did not send `update response` information to Data Converter when the proxy package within the api-go module was used in a gRPC proxy prior to transmission. This resulted in information contained within the `update response` field not having Data Converter transformations (e.g. encryption) applied. This is an issue only when using the UpdateWorkflowExecution APIs (released on 13th January 2025) with a proxy leveraging the api-go library before version 1.44.1. Other data fields were correctly sent to Data Converter. This issue does not impact the Data Converter server. Data was encrypted in transit. Temporal Cloud services are not impacted.

0%
Низкий
12 месяцев назад
github логотип
GHSA-q9w6-cwj4-gf4p

Unencrypted transmission in Temporal api-go library

0%
Низкий
12 месяцев назад

Уязвимостей на страницу