news.mlab.sh
Back to the feed
vulnerability

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

High
Image: The Hacker News
Summary

HashiCorp, Veeam, and Django have released critical patches to address several vulnerabilities, including a cross-tenant credential reuse flaw in Terraform MCP Server, a multi-tenant console credential impersonation issue in Veeam Service Provider Console, and a remote code execution vulnerability in Django's spatial data layer. The most severe vulnerability, a 10.0 CVSS score, involves Terraform MCP Server, allowing an attacker to reuse a user's token across multiple sessions. Veeam’s console has four fixes, with a 9.5 CVSS score related to impersonating a managed agent. Django’s spatial data layer vulnerability, while requiring a staff account, can lead to remote code execution. These patches are crucial for mitigating potential attacks, especially given the ongoing scrutiny of Django’s GIS code.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.