In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
References
Link | Resource |
---|---|
https://www.jetbrains.com/privacy-security/issues-fixed/ | Vendor Advisory |
Configurations
Information
Published : 2022-12-08 10:15
Updated : 2022-12-12 08:33
NVD link : CVE-2022-46831
Mitre link : CVE-2022-46831
JSON object : View
CWE
CWE-1188
Insecure Default Initialization of Resource
Products Affected
jetbrains
- teamcity