SECURITY·중요도 9·2026. 08. 05.·The Hacker News

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

── KO ──────────────────

Veeam, Terraform MCP, Django의 심각한 취약점이 패치되었다.

HashiCorp, Veeam, Django Software Foundation이 Terraform MCP Server, Veeam Service Provider Console, Django의 11개의 취약점을 패치하였다. 가장 심각한 취약점 중 하나는 Veeam 콘솔의 인증되지 않은 결함으로, 관리되는 에이전트의 자격 증명을 유출할 수 있는 문제이며 CVSS 점수는 9.5이다. 또한 HashiCorp의 MCP 서버에서 사용자의 Terraform 토큰이 재사용될 수 있는 크로스 테넌트 결함도 발견되었다.


── EN ──────────────────

Veeam, Terraform MCP, and Django have patched critical vulnerabilities.

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. Among the most critical is an unauthenticated flaw in Veeam's console that exposes managed agent credentials, rated at 9.5 on the CVSS scale. Additionally, a cross-tenant flaw in HashiCorp’s MCP server allows a user's Terraform token to be reused by subsequent users.

원문 보기 →목록으로