漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Field in api-go proxy not transformed before version 1.44.1
Vulnerability Description
The Temporal api-go library prior to version 1.44.1 did not send `update response` information to Data Converter when the proxy package within the api-go module was used in a gRPC proxy prior to transmission. This resulted in information contained within the `update response` field not having Data Converter transformations (e.g. encryption) applied. This is an issue only when using the UpdateWorkflowExecution APIs (released on 13th January 2025) with a proxy leveraging the api-go library before version 1.44.1. Other data fields were correctly sent to Data Converter. This issue does not impact the Data Converter server. Data was encrypted in transit. Temporal Cloud services are not impacted.
CVSS Information
N/A
Vulnerability Type
敏感数据加密缺失
Vulnerability Title
api-go 安全漏洞
Vulnerability Description
api-go是temporal开源的一个接口程序。 api-go 1.44.1之前版本存在安全漏洞,该漏洞源于使用代理时未将update response信息发送至Data Converter。
CVSS Information
N/A
Vulnerability Type
N/A