CyberSecurity News
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
AI summary
HashiCorp, Veeam, and the Django Software Foundation have addressed 11 vulnerabilities in their respective products, including Terraform MCP Server, Veeam Service Provider Console, and Django. The most severe issues include an unauthenticated flaw in Veeam's console that exposes a managed agent's credentials, with a severity rating of 9.5. A critical cross-tenant flaw was also found in HashiCorp's MCP server, allowing one user's Terraform token to be reused by later users. These vulnerabilities have been patched by the respective companies. The cross-tenant bug in HashiCorp's MCP server has a severity rating of 10.0, indicating a high level of risk. The patches aim to mitigate these critical flaws and prevent potential exploitation.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

