« Volver al listado

CVE-2025-14986

Estado: AplazadaBaja (1.3)—

When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates for the embedded StartWorkflowExecutionRequest using its Namespace field rather than the outer, authorized ExecuteMultiOperationRequest.Namespace. This allows a caller authorized for one namespace to bypass that namespace's limits/policies by setting the embedded start request's namespace to a different namespace. The workflow is still created in the outer (authorized) namespace; only validation/gating is performed under the wrong namespace context. This issue affects Temporal: from 1.24.0 through 1.29.1. Fixed in 1.27.4, 1.28.2, 1.29.2.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-14986",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-14986",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-02T15:30:54.551721Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "security@temporal.io",
        "cvssData": {
          "Safety": "NEGLIGIBLE",
          "version": "4.0",
          "Recovery": "USER",
          "baseScore": 1.3,
          "Automatable": "YES",
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:X/RE:L/U:Green",
          "exploitMaturity": "UNREPORTED",
          "providerUrgency": "GREEN",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "LOW",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "LOW",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "security@temporal.io",
      "affectedData": [
        {
          "repo": "https://github.com/temporalio/temporal",
          "vendor": "Temporal",
          "product": "Temporal",
          "versions": [
            {
              "status": "affected",
              "version": "1.24.0",
              "versionType": "semver",
              "lessThanOrEqual": "1.29.1"
            },
            {
              "status": "affected",
              "version": "1.24.0",
              "versionType": "semver",
              "lessThanOrEqual": "1.28.1"
            },
            {
              "status": "affected",
              "version": "1.24.0",
              "versionType": "semver",
              "lessThanOrEqual": "1.27.3"
            }
          ],
          "packageName": "temporal",
          "collectionURL": "https://github.com/temporalio/temporal",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-12-30T21:15:42.773",
  "references": [
    {
      "url": "https://github.com/temporalio/temporal/releases/tag/v1.27.4",
      "source": "security@temporal.io"
    },
    {
      "url": "https://github.com/temporalio/temporal/releases/tag/v1.28.2",
      "source": "security@temporal.io"
    },
    {
      "url": "https://github.com/temporalio/temporal/releases/tag/v1.29.2",
      "source": "security@temporal.io"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@temporal.io",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates for the embedded StartWorkflowExecutionRequest using its Namespace field rather than the outer, authorized ExecuteMultiOperationRequest.Namespace. This allows a caller authorized for one namespace to bypass that namespace's limits/policies by setting the embedded start request's namespace to a different namespace. The workflow is still created in the outer (authorized) namespace; only validation/gating is performed under the wrong namespace context.\nThis issue affects Temporal: from 1.24.0 through 1.29.1. Fixed in 1.27.4, 1.28.2, 1.29.2."
    },
    {
      "lang": "es",
      "value": "Cuando frontend.enableExecuteMultiOperation está habilitado, el servidor puede aplicar validación con ámbito de espacio de nombres y puertas de características para la StartWorkflowExecutionRequest incrustada usando su campo Namespace en lugar del Namespace de la ExecuteMultiOperationRequest externa y autorizada. Esto permite a un llamador autorizado para un espacio de nombres eludir los límites/políticas de ese espacio de nombres al establecer el espacio de nombres de la solicitud de inicio incrustada a un espacio de nombres diferente. El flujo de trabajo aún se crea en el espacio de nombres externo (autorizado); solo la validación/aplicación de puertas se realiza bajo el contexto de espacio de nombres incorrecto.\nEste problema afecta a Temporal: desde 1.24.0 hasta 1.29.1. Corregido en 1.27.4, 1.28.2, 1.29.2."
    }
  ],
  "lastModified": "2026-06-17T08:36:53.560",
  "sourceIdentifier": "security@temporal.io"
}