CVE-2022-46829: High severity jetbrains gateway vulnerability
Published Dec 8, 2022
·Updated
In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.
Affected Software
1 affected component
JetBrains JetBrains Gateway<2022.3
Event History
Dec 8, 2022
CVE Published
via MITRE·05:38 PM
Data Sourced
via MITRE·05:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-46829?
CVE-2022-46829 has a medium severity level due to the potential for unauthorized access without token validation.
2
How do I fix CVE-2022-46829?
To fix CVE-2022-46829, upgrade to version 2022.3 or later of JetBrains Gateway.
3
What are the risks associated with CVE-2022-46829?
The risks of CVE-2022-46829 include unauthorized access to JetBrains Gateway services, which could lead to data exposure.
4
Who is affected by CVE-2022-46829?
Users of JetBrains Gateway versions prior to 2022.3 are affected by CVE-2022-46829.
5
Is CVE-2022-46829 exploitable remotely?
Yes, CVE-2022-46829 can be exploited remotely if a user connects to a host that consents to a connection without proper token verification.