PT-2025-38233 · Cisa · Thorium

Published

2025-09-17

·

Updated

2025-09-17

·

CVE-2025-35434

CVSS v3.1
4.2
VectorAV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with access to a Thorium cluster could impersonate the Elasticsearch service. Fixed in 1.1.2.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2025-35434

Affected Products

Thorium