PT-2025-54225 · Temporal · Temporal
CVE-2025-14987
·
Publicado
2025-12-30
·
Atualizado
2026-07-30
CVSS v4.0
5.3
Média
| Vetor | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Temporal versions through 1.29.1
Description
When the
system.enableCrossNamespaceCommands setting is enabled, the Temporal server allows specific workflow task commands—including StartChildWorkflowExecution, SignalExternalWorkflowExecution, and RequestCancelExternalWorkflowExecution—to operate on a namespace different from the one authorized at the gRPC boundary. The frontend authorizes RespondWorkflowTaskCompleted based on the outer request namespace, but the history service later resolves and executes the command using the namespace embedded in command attributes without re-authorizing the caller for that target namespace. This can potentially allow a worker authorized for one namespace to create, signal, or cancel workflows in another namespace.Recommendations
Update to Temporal version 1.27.4 or later.
Update to Temporal version 1.28.2 or later.
Update to Temporal version 1.29.2 or later.
Exploit
Correção
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Temporal