CVE-2025-35434
CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with access to a Thorium cluster could impersonate the Elasticsearch service. Fixed in 1.1.2.
Vendor
Product
CWE
Yayın Tarihi
2025-09-17 17:15:43
Güncelleme
2025-09-23 15:44:11
Source Identifier
9119a7d8-5eab-497f-8521-727c672e3725
KEV Date Added
-