CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-43016: In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session

5.4 CVSS

Description

In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session

Classification

CVE ID: CVE-2025-43016

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.4

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Problem Types

CWE-23

Affected Products

Vendor: JetBrains

Product: Rider

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.0% (probability of being exploited)

EPSS Percentile: 0.06% (scored less or equal to compared to others)

EPSS Date: 2025-05-24 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-43016
https://www.jetbrains.com/privacy-security/issues-fixed/

Timeline