7.5 HIGH
- CVSS version: 3.1
- Attack vector (AV):
- Attack complexity (AC):
- Privileges required (PR):
- User interaction (UI):
- Scope (S):
- Confidentiality impact (C):
- Integrity impact (I):
- Availability impact (A):
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
31 packages
- temporal
- tempora_lgc
- temporalite
- temporal-cli
- temporal_capi
- temporal-ui-server
- gnomeExtensions.tempomate
- haskellPackages.temporary
- python312Packages.tempora
- python313Packages.tempora
- python314Packages.tempora
- tests.haskell.incremental
- haskellPackages.temporary-rc
- python312Packages.temporalio
- python313Packages.temporalio
- python314Packages.temporalio
- haskellPackages.temporal-media
- terraform-providers.temporalcloud
- postgresqlPackages.temporal_tables
- haskellPackages.temporal-api-protos
- haskellPackages.temporary-resourcet
- postgresql13Packages.temporal_tables
- postgresql14Packages.temporal_tables
- postgresql15Packages.temporal_tables
- postgresql16Packages.temporal_tables
- postgresql17Packages.temporal_tables
- postgresql18Packages.temporal_tables
- haskellPackages.temporal-music-notation
- haskellPackages.temporal-music-notation-demo
- terraform-providers.temporalio_temporalcloud
- haskellPackages.temporal-music-notation-western
- @LeSuisse accepted
- @LeSuisse published on GitHub
S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern)
A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3. Thanks to william_goodfellow for reporting this vulnerability.
References
-
https://grafana.com/security/security-advisories/cve-2026-28377 vendor-advisory
Affected products
- ==2.10.3
Matching in nixpkgs
Ignored packages (31)
pkgs.temporal
Microservice orchestration platform which enables developers to build scalable applications without sacrificing productivity or reliability
pkgs.tempora_lgc
Tempora font
pkgs.temporalite
Experimental distribution of Temporal that runs as a single process
pkgs.temporal-cli
Command-line interface for running Temporal Server and interacting with Workflows, Activities, Namespaces, and other parts of Temporal
pkgs.temporal_capi
A Rust implementation of ECMAScript's Temporal API
pkgs.temporal-ui-server
Golang Server for Temporal Web UI
pkgs.gnomeExtensions.tempomate
Effortless time tracking in Jira Tempo timesheets!
pkgs.haskellPackages.temporary
Portable temporary file and directory support
pkgs.python312Packages.tempora
Objects and routines pertaining to date and time
pkgs.python313Packages.tempora
Objects and routines pertaining to date and time
pkgs.python314Packages.tempora
Objects and routines pertaining to date and time
pkgs.tests.haskell.incremental
None
pkgs.haskellPackages.temporary-rc
Portable temporary file and directory support for Windows and Unix, based on code from Cabal
pkgs.python312Packages.temporalio
Temporal Python SDK
pkgs.python313Packages.temporalio
Temporal Python SDK
pkgs.python314Packages.temporalio
Temporal Python SDK
pkgs.haskellPackages.temporal-media
data types for temporal media
pkgs.terraform-providers.temporalcloud
None
pkgs.postgresqlPackages.temporal_tables
Temporal Tables PostgreSQL Extension
pkgs.haskellPackages.temporal-api-protos
None
-
nixos-unstable 2025.10.1.0
- nixpkgs-unstable 2025.10.1.0
- nixos-unstable-small 2025.10.1.0
-
nixos-25.11 2025.10.1.0
- nixos-25.11-small 2025.10.1.0
- nixpkgs-25.11-darwin 2025.10.1.0
pkgs.haskellPackages.temporary-resourcet
Portable temporary files and directories with automatic deletion
pkgs.postgresql13Packages.temporal_tables
Temporal Tables PostgreSQL Extension
pkgs.postgresql14Packages.temporal_tables
Temporal Tables PostgreSQL Extension
pkgs.postgresql15Packages.temporal_tables
Temporal Tables PostgreSQL Extension
pkgs.postgresql16Packages.temporal_tables
Temporal Tables PostgreSQL Extension
pkgs.postgresql17Packages.temporal_tables
Temporal Tables PostgreSQL Extension
pkgs.postgresql18Packages.temporal_tables
Temporal Tables PostgreSQL Extension
pkgs.haskellPackages.temporal-music-notation
music notation
pkgs.haskellPackages.temporal-music-notation-demo
generates midi from score notation
Package maintainers
-
@WilliButz Willi Butz <willibutz@posteo.de>