JetBrains / Toolbox
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-43014 | In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation | MEDIUM | 6.5 | Apr 17, 2025 |
| CVE-2025-43013 | In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible | HIGH | 7.5 | Apr 17, 2025 |
| CVE-2025-43012 | In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible | CRITICAL | 9.8 | Apr 17, 2025 |
| CVE-2025-42921 | In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin | MEDIUM | 6.5 | Apr 17, 2025 |
| CVE-2024-24943 | In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image | MEDIUM | 5.5 | Feb 6, 2024 |
| CVE-2022-48481 | In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible | HIGH | 7.8 | Apr 28, 2023 |
| CVE-2020-25207 | JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler. | CRITICAL | 9.8 | Nov 16, 2020 |
| CVE-2020-25013 | JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler. | HIGH | 7.5 | Nov 16, 2020 |
| CVE-2020-15827 | In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file. | HIGH | 7.5 | Aug 8, 2020 |
| CVE-2019-18368 | In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible. | HIGH | 7.3 | Oct 31, 2019 |
| CVE-2019-14959 | JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection. | MEDIUM | 5.9 | Oct 2, 2019 |
Showing 1 to 11 of 11 CVEs