PT-2025-6423 · Temporal · Api-Go

Published

2025-02-12

·

Updated

2025-03-13

·

CVE-2025-1243

CVSS v4.0

2.0

Low

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Temporal api-go library versions prior to 1.44.1
Description The issue arises when using the UpdateWorkflowExecution APIs with a proxy leveraging the api-go library before version 1.44.1. In this scenario, the update response information is not sent to Data Converter, resulting in the information contained within the update response field not having Data Converter transformations, such as encryption, applied. Other data fields are correctly sent to Data Converter. This issue does not impact the Data Converter server, and data was encrypted in transit. Temporal Cloud services are not impacted.
Recommendations For versions prior to 1.44.1, update to version 1.44.1 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the UpdateWorkflowExecution APIs with a proxy leveraging the api-go library until the update is applied.

Fix

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-1243
GHSA-Q9W6-CWJ4-GF4P
GO-2025-3462
OPENSUSE-SU-2025:14889-1

Affected Products

Api-Go