In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
toolbox
Vendor: jetbrains
Security Vulnerability Index
Page 1 / 2In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible
In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible
In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin
In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image
In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible
JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler.
JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler.
In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.
In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.