vulnerability
JetBrains TeamCity: CVE-2022-46831: Connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators (TW-78416)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
6 | (AV:N/AC:L/Au:M/C:P/I:P/A:P) | Dec 8, 2022 | Oct 15, 2024 | Jul 2, 2025 |
Severity
6
CVSS
(AV:N/AC:L/Au:M/C:P/I:P/A:P)
Published
Dec 8, 2022
Added
Oct 15, 2024
Modified
Jul 2, 2025
Description
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
Solution
jetbrains-teamcity-upgrade-latest

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.