vulnerability

JetBrains TeamCity: CVE-2022-46831: Connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators (TW-78416)

Severity
6
CVSS
(AV:N/AC:L/Au:M/C:P/I:P/A:P)
Published
Dec 8, 2022
Added
Oct 15, 2024
Modified
Jul 2, 2025

Description

In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.

Solution

jetbrains-teamcity-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.