CVE Vulnerabilities

CVE-2025-43014

Missing Critical Step in Authentication

Published: Apr 17, 2025 | Modified: Apr 23, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation

Weakness

The product implements an authentication technique, but it skips a step that weakens the technique.

Affected Software

NameVendorStart VersionEnd Version
ToolboxJetbrains*2.6 (excluding)

References