Signature Verification Vulnerability in JetBrains ToolBox
CVE-2020-15827

7.5HIGH

Key Information:

Vendor
Jetbrains
Status
Vendor
CVE Published:
8 August 2020

Summary

In JetBrains ToolBox prior to version 1.17.6856, a vulnerability existed where the signature verification process failed to adequately validate the jetbrains-toolbox.exe file. This oversight could allow unauthorized executions on systems using this software, potentially exposing users to further security threats. It is advisable for users to upgrade to the latest version to mitigate any associated risks.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.