CVE-2022-36322
About
In JetBrains TeamCity before 2022.04.2 build parameter injection was possible
Rainforest analyst review
In TeamCity before 2022.04.2, a user could inject build parameters, a limited integrity-and-confidentiality issue that requires an authenticated account with some privilege to reach. It is not a remote-unauthenticated takeover; it is a lower-privileged user bending the build configuration in ways they shouldn't be able to. The 5.4 reflects that the impact is partial and the door needs a valid login.
That said, CI systems are high-value ground because they hold source, secrets, and deployment reach, so parameter manipulation there is worth taking seriously even at medium severity. The realistic threat model is an insider or a compromised low-tier account rather than a mass-scanning botnet; there is nothing here for opportunistic internet attackers, which caps the exploitation tempo.
We would weigh this by who can log into the given TeamCity instance and how sensitive its pipelines are, rather than by the CVSS alone. A build server that authenticates a broad set of developers and touches production deserves the patch promptly; a locked-down instance with a handful of trusted operators can be scheduled normally. The point is proportionality: the precondition is doing most of the risk-reduction already.
References
Related CVEs
No related CVEs.
Frequently asked questions
What is CVE-2022-36322?
In JetBrains TeamCity before 2022.04.2 build parameter injection was possible
How severe is CVE-2022-36322?
CVE-2022-36322 carries a CVSS 3.1 base score of 5.4, rated medium. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 59 out of 100, in the elevated band.
How is CVE-2022-36322 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N): attack vector Network, attack complexity Low, privileges required Low, user interaction None. Impact on confidentiality Low, integrity Low and availability None.
Which products are affected by CVE-2022-36322?
Public advisories list the following as affected: teamcity. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2022-36322?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
