Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/temporalio/temporal: CVE-2024-2689 #2709

Closed
GoVulnBot opened this issue Apr 10, 2024 · 1 comment
Closed

Comments

@GoVulnBot
Copy link

CVE-2024-2689 references github.com/temporalio/temporal, which may be a Go module.

Description:
Denial of Service in Temporal Server prior to version 1.20.5, 1.21.6, and 1.22.7 allows an authenticated user who has permissions to interact with workflows and has crafted an invalid UTF-8 string for submission to potentially cause a crashloop. If left unchecked, the task containing the invalid UTF-8 will become stuck in the queue, causing an increase in queue lag. Eventually, all processes handling these queues will become stuck and the system will run out of resources. The workflow ID of the failing task will be visible in the logs, and can be used to remove that workflow as a mitigation. Version 1.23 is not impacted. In this context, a user is an operator of Temporal Server.

References:

Cross references:

See doc/triage.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/temporalio/temporal
      vulnerable_at: 1.23.0
      packages:
        - package: Temporal Server
cves:
    - CVE-2024-2689
references:
    - web: https://github.com/temporalio/temporal/releases

@tatianab
Copy link
Contributor

Duplicate of #2689

@tatianab tatianab marked this as a duplicate of #2689 Apr 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants