—
GO-2024-2689
Temporal Server Denial of Service in go.temporal.io/server
Quick fix
GO-2024-2689 — go.temporal.io/server: upgrade to the fixed version with the command below.
go get go.temporal.io/server@v1.20.5Details
Temporal Server Denial of Service in go.temporal.io/server
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/advisories/GHSA-wmxc-v39r-p9wf[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2024-2689[ADVISORY]
- https://github.com/temporalio/temporal/commit/2099dfd945accbf794404c3b8d990d109de19f06[WEB]
- https://github.com/temporalio/temporal/commit/679e3dc2ca8bd39e02c760f686cc8807f817bbfd[WEB]
- https://github.com/temporalio/temporal/commit/f1fab97129f964dcca17d1f7c344f38666d1ee5f[WEB]
- https://github.com/temporalio/temporal/releases[WEB]