Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug — [https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiGDed_n3TJG
What’s new: Veeam, HashiCorp, and Django have released patches for critical vulnerabilities. Notable issues include a CVSS 10.0 cross-tenant bug in HashiCorp’s Terraform MCP server, a CVSS 9.5 unauthenticated flaw in Veeam’s Service Provider Console, and a critical vulnerability in Django’s GeoDjango framework that could lead to remote code execution.
Who’s affected
Users of Veeam Service Provider Console versions prior to 9.3.0.35057, HashiCorp Terraform MCP Server versions prior to 1.1.0, and Django versions 6.0.8 or 5.2.17 are at risk. The vulnerabilities may expose sensitive data or allow unauthorized access depending on configuration.
What to do
- Update Veeam Service Provider Console to version 9.3.0.35057 or later.
- Update HashiCorp Terraform MCP Server to version 1.1.0 or later.
- Update Django to version 6.0.8 or 5.2.17.
- For immediate protection, restrict network access to the Streamable HTTP listener in Terraform MCP and treat session IDs as sensitive.



