CVE-2023-3485 Vulnerability Details

  /     /     /  

CVE-2023-3485 Metadata Quick Info

CVE Published: 30/06/2023 | CVE Updated: 28/10/2024 | CVE Year: 2023
Source: Temporal | Vendor: Temporal Technologies Inc. | Product: Temporal Server
Status : PUBLISHED

CVE-2023-3485 Description

Insecure defaults in open-source Temporal Server before version 1.20 on all platforms allows an attacker to craft a task token with access to a namespace other than the one specified in the request. Creation of this task token must be done outside of the normal Temporal server flow. It requires the namespace UUID and information from the workflow history for the target namespace. Under these conditions, it is possible to interfere with pending tasks in other namespaces, such as marking a task failed or completed. If a task is targeted for completion by the attacker, the targeted namespace must also be using the same data converter configuration as the initial, valid, namespace for the task completion payload to be decoded by workers in the target namespace.

Metrics

CVSS Version: 3.1 | Base Score: 3 LOW
Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L

l➤ Exploitability Metrics:
    Attack Vector (AV)* LOCAL
    Attack Complexity (AC)* HIGH
    Privileges Required (PR)* HIGH
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* NONE
    Integrity Impact (I)* LOW
    Availability Impact (A)* LOW

Weakness Enumeration (CWE)

CWE-ID: CWE-863
CWE Name: CWE-863 Incorrect Authorization3 Incorrect Authorization
Source: Temporal Technologies Inc.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-114
CAPEC Description: CAPEC-114 Authentication Abuse Authentication Abuse


Source: NVD (National Vulnerability Database).