CVE-2025-1243 describes a vulnerability in the Temporal api-go library, specifically versions prior to 1.44.1, where the 'update response' information from UpdateWorkflowExecution APIs was not sent to Data Converter when using the proxy package in a gRPC proxy. This omission meant that Data Converter transformations, such as encryption, were not applied to this specific field, potentially exposing sensitive information. The vulnerability has a low CVSS score of 2.0, indicating a local attack vector with low complexity and limited impact on confidentiality. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Temporal Technologies, Inc. | Api-Go Library | >= 0, < 1.44.1CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.