Toolbox
by Jetbrains
CVEs (11)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-25207 | Cri | 0.64 | 9.8 | 0.05 | Nov 16, 2020 | JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler. | ||
| CVE-2025-43012 | Hig | 0.54 | 8.3 | 0.01 | Apr 17, 2025 | In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible | ||
| CVE-2020-25013 | Hig | 0.49 | 7.5 | 0.01 | Nov 16, 2020 | JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler. | ||
| CVE-2020-15827 | Hig | 0.49 | 7.5 | 0.01 | Aug 8, 2020 | In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file. | ||
| CVE-2019-18368 | Hig | 0.48 | 7.3 | 0.01 | Oct 31, 2019 | In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible. | ||
| CVE-2025-43013 | Med | 0.45 | 6.9 | 0.00 | Apr 17, 2025 | In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible | ||
| CVE-2025-43014 | Med | 0.40 | 6.1 | 0.00 | Apr 17, 2025 | In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation | ||
| CVE-2019-14959 | Med | 0.38 | 5.9 | 0.01 | Oct 2, 2019 | JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection. | ||
| CVE-2024-24943 | Med | 0.34 | 5.3 | 0.00 | Feb 6, 2024 | In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image | ||
| CVE-2022-48481 | Med | 0.34 | 5.2 | 0.00 | Apr 28, 2023 | In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible | ||
| CVE-2025-42921 | Med | 0.27 | 4.2 | 0.00 | Apr 17, 2025 | In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin |
- risk 0.64cvss 9.8epss 0.05
JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler.
- risk 0.54cvss 8.3epss 0.01
In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible
- risk 0.49cvss 7.5epss 0.01
JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler.
- risk 0.49cvss 7.5epss 0.01
In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.
- risk 0.48cvss 7.3epss 0.01
In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.
- risk 0.45cvss 6.9epss 0.00
In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible
- risk 0.40cvss 6.1epss 0.00
In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
- risk 0.38cvss 5.9epss 0.01
JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.
- risk 0.34cvss 5.3epss 0.00
In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image
- risk 0.34cvss 5.2epss 0.00
In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible
- risk 0.27cvss 4.2epss 0.00
In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin