U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-2689

Change History

New CVE Received by NIST 4/03/2024 6:15:07 PM

Action Type Old Value New Value
Added CVSS V3.1

								
							
							
						
Temporal Technologies Inc. AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
Added CWE

								
							
							
						
Temporal Technologies Inc. CWE-20
Added Description

								
							
							
						
Denial of Service in Temporal Server prior to version 1.20.5, 1.21.6, and 1.22.7 allows an authenticated user who has permissions to interact with workflows and has crafted an invalid UTF-8 string for submission to potentially cause a crashloop. If left unchecked, the task containing the invalid UTF-8 will become stuck in the queue, causing an increase in queue lag. Eventually, all processes handling these queues will become stuck and the system will run out of resources. The workflow ID of the failing task will be visible in the logs, and can be used to remove that workflow as a mitigation. Version 1.23 is not impacted. In this context, a user is an operator of Temporal Server.
Added Reference

								
							
							
						
Temporal Technologies Inc. https://github.com/temporalio/temporal/releases [No types assigned]