Showing 1 vulnerability on this page for Temporal UI Server

Signals CISA KEV Ransomware Nuclei
Temporal Technologies, Inc. vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Temporal UI Server may set OAuth credential cookies without Secure behind a TLS-terminating reverse proxy

When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to Temporal UI Server over HTTP, affected versions derive authentication-cookie Secure attributes from the proxy-to-server connection. Temporal UI Server can therefore issue access-token cookies, and refresh-token cookies when provided by the identity provider, without Secure even though the browser completed login over HTTPS. A victim who visits attacker-controlled content whi

CWE-614Aug 11, 2026
CVSS2.3v4.0EPSS0.28%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX