Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug — [https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiGDed_n3TJG

veeam-terraform-mcp-django-patch-critical-flaws-led-by-cvss-100-cross-tenant-bug

What’s new: Veeam, HashiCorp, and Django have released patches for critical vulnerabilities. Notable issues include a CVSS 10.0 cross-tenant bug in HashiCorp’s Terraform MCP server, a CVSS 9.5 unauthenticated flaw in Veeam’s Service Provider Console, and a critical vulnerability in Django’s GeoDjango framework that could lead to remote code execution.

Who’s affected

Users of Veeam Service Provider Console versions prior to 9.3.0.35057, HashiCorp Terraform MCP Server versions prior to 1.1.0, and Django versions 6.0.8 or 5.2.17 are at risk. The vulnerabilities may expose sensitive data or allow unauthorized access depending on configuration.

What to do

  • Update Veeam Service Provider Console to version 9.3.0.35057 or later.
  • Update HashiCorp Terraform MCP Server to version 1.1.0 or later.
  • Update Django to version 6.0.8 or 5.2.17.
  • For immediate protection, restrict network access to the Streamable HTTP listener in Terraform MCP and treat session IDs as sensitive.

Sources