ZeroHour

CVE-2022-46831

CVSS 3.1
4.9 medium
EPSS
<1%p38
Published
()
Modified
Description

In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.

Vendors
jetbrains
Products
teamcity
Weakness
CWE-453, CWE-1188
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.