漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
terraform-mcp-server vulnerable to server side request forgery leading to token exposure
Vulnerability Description
The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This vulnerability, CVE-2026-14869, is fixed in terraform-mcp-server 1.1.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
HashiCorp Tooling 服务端请求伪造漏洞
Vulnerability Description
HashiCorp Tooling是美国HashiCorp公司的系统工具组件。 HashiCorp Tooling 1.1.0之前版本存在服务端请求伪造漏洞,该漏洞源于streamable-HTTP传输中存在服务端请求伪造问题,可能导致未经身份验证的远程客户端将服务器的Terraform API请求以及服务器端授权令牌重定向到攻击者控制的端点。
CVSS Information
N/A
Vulnerability Type
N/A