CVE-2025-42921: Medium severity jetbrains toolbox app vulnerability
Published Apr 17, 2025
·Updated
In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin
Affected Software
2 affected components
JetBrains Toolbox App<2.6
JetBrains Toolbox<2.6
Event History
Apr 17, 2025
CVE Published
via MITRE·03:56 PM
Data Sourced
via MITRE·03:56 PM
DescriptionSeverityWeakness
Jun 14, 57318
Event
via FIRST·11:58 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-42921?
CVE-2025-42921 is classified as a moderate severity vulnerability due to its potential for unauthorized SSH access.
2
How do I fix CVE-2025-42921?
To fix CVE-2025-42921, upgrade the JetBrains Toolbox App to version 2.6 or later where host key verification has been implemented.
3
What does CVE-2025-42921 affect?
CVE-2025-42921 affects the JetBrains Toolbox App versions prior to 2.6 due to missing host key verification in the SSH plugin.
4
What is the nature of the vulnerability identified in CVE-2025-42921?
CVE-2025-42921 involves a security oversight where the SSH plugin does not verify host keys, potentially allowing man-in-the-middle attacks.
5
Is CVE-2025-42921 being actively exploited?
As of the latest reports, there are no indications that CVE-2025-42921 is being actively exploited in the wild.