« Volver al listado

Jetbrains

Jetbrains Toolbox: vulnerabilidades y CVE

Jetbrains Toolbox tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE11
Últimos 12 meses0
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-43014Media (6.5)0.23%—17 abr 2025
In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
CVE-2025-43013Alta (7.5)0.15%—17 abr 2025
In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible
CVE-2025-43012Crítica (9.8)0.63%—17 abr 2025
In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible
CVE-2025-42921Media (6.5)0.20%—17 abr 2025
In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin
CVE-2024-24943Media (5.5)0.41%—6 feb 2024
In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image
CVE-2022-48481Alta (7.8)0.21%—28 abr 2023
In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible
CVE-2020-25207Crítica (9.8)4.6%—16 nov 2020
JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler.
CVE-2020-25013Alta (7.5)1.4%—16 nov 2020
JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler.
CVE-2020-15827Alta (7.5)0.69%—8 ago 2020
In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.
CVE-2019-18368Alta (7.3)1.0%—31 oct 2019
In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.
CVE-2019-14959Media (5.9)0.66%—2 oct 2019
JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application2
  2. T1059 Command and Scripting Interpreter1
  3. T1212 Exploitation for Credential Access1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Jetbrains