CVE-2024-2689
MEDIUM4.4EPSS 0.07%Temporal Server Denial of Service in go.temporal.io/server
Published: 4/4/2024Modified: 3/3/2026
Description
Temporal Server Denial of Service in go.temporal.io/server
Affected packages (2)
- Go/github.com/temporalio/temporal>= 1.22.0-rc1, < 1.22.7
- Go/go.temporal.io/serverfrom 0, < 1.20.5, >= 1.21.0, < 1.21.6, >= 1.22.0-rc1, < 1.22.7
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.4 | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H |
References (7)
- ADVISORYhttps://github.com/advisories/GHSA-wmxc-v39r-p9wf
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2024-2689
- PATCHhttps://github.com/temporalio/temporal
- WEBhttps://github.com/temporalio/temporal/commit/2099dfd945accbf794404c3b8d990d109de19f06
- WEBhttps://github.com/temporalio/temporal/commit/679e3dc2ca8bd39e02c760f686cc8807f817bbfd
- WEBhttps://github.com/temporalio/temporal/commit/f1fab97129f964dcca17d1f7c344f38666d1ee5f
- WEBhttps://github.com/temporalio/temporal/releases