First published: Thu Dec 08 2022(Updated: )
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
Credit: security@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jetbrains Teamcity | >=2022.10<=2022.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this JetBrains TeamCity vulnerability is CVE-2022-46831.
CVE-2022-46831 has a severity level of medium (4.9).
CVE-2022-46831 affects JetBrains TeamCity versions between 2022.10 and 2022.10.1.
CVE-2022-46831 allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
Yes, JetBrains has provided a fix for CVE-2022-46831. It is recommended to update to a version higher than 2022.10.1.