漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
Vulnerability Description
The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. This vulnerability, CVE-2026-16498, is fixed in terraform-mcp-server 1.1.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Vulnerability Type
对错误会话暴露数据元素
Vulnerability Title
HashiCorp Tooling 会话机制问题漏洞
Vulnerability Description
HashiCorp Tooling是美国HashiCorp公司的系统工具组件。 HashiCorp Tooling 1.1.0之前版本存在会话机制问题漏洞,该漏洞源于streamable-HTTP stateless传输模式下的跨租户凭证重用问题,可能导致一个用户的Terraform token被用于代表后续用户执行工具调用。
CVSS Information
N/A
Vulnerability Type
N/A