CVE-2020-15827 describes a critical vulnerability in JetBrains ToolBox versions prior to 1.17.6856, where the jetbrains-toolbox.exe file was not properly signature-verified. This oversight, categorized as CWE-347 (Improper Verification of Cryptographic Signature), allows for potential integrity compromise of the application. With a CVSS score of 7.5 (HIGH), this vulnerability is remotely exploitable with low attack complexity, posing a significant risk of high impact to integrity without requiring user interaction. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there's minimal community discussion or media coverage, the absence of active exploitation should not diminish its potential severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.17, < 1.17.6856CPE matchmatch criteria | cpe:2.3:a:jetbrains:toolbox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.