CVE-2025-43014: Medium severity jetbrains toolbox app vulnerability
Published Apr 17, 2025
·Updated
In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
Affected Software
2 affected components
JetBrains Toolbox App<2.6
JetBrains Toolbox<2.6
Event History
Apr 17, 2025
CVE Published
via MITRE·03:56 PM
Data Sourced
via MITRE·03:56 PM
DescriptionSeverityWeakness
Jun 14, 57318
Event
via FIRST·11:59 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-43014?
CVE-2025-43014 has been classified as a moderate severity vulnerability due to the lack of user confirmation when establishing SSH connections.
2
How do I fix CVE-2025-43014?
To mitigate CVE-2025-43014, upgrade to JetBrains Toolbox App version 2.6 or later, which addresses this vulnerability.
3
What does CVE-2025-43014 affect?
CVE-2025-43014 affects the JetBrains Toolbox App versions prior to 2.6, specifically the SSH plugin.
4
What type of vulnerability is CVE-2025-43014?
CVE-2025-43014 is an authentication vulnerability that allows SSH connections without sufficient user confirmation.
5
Who is impacted by CVE-2025-43014?
Users of JetBrains Toolbox App versions before 2.6 are impacted by CVE-2025-43014.