In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
References
Link | Resource |
---|---|
https://www.jetbrains.com/privacy-security/issues-fixed/ | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2022-12-08 18:15
Updated : 2022-12-12 16:33
NVD link : CVE-2022-46831
Mitre link : CVE-2022-46831
JSON object : View
Products Affected
jetbrains
- teamcity
CWE
CWE-1188
Insecure Default Initialization of Resource