01 Record index
Temporal UI Server may set OAuth credential cookies without Secure behind a TLS-terminating reverse proxy
Temporal UI Server may set OAuth credential cookies without Secure behind a TLS-terminating reverse proxy
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
Upgrade to Temporal UI Server v2.53.2 or later. The fix derives the authentication-cookie Secure attribute from the configured browser-facing OAuth callback URL instead of the proxy-to-server connection and applies that decision consistently to all authentication cookies.