CVE-2025-35434 - CISA Thorium does not validate TLS connections to Elasticsearch
CVE ID : CVE-2025-35434
Published : Sept. 17, 2025, 5:15 p.m. | 54 minutes ago
Description : CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with access to a Thorium cluster could impersonate the Elasticsearch service. Fixed in 1.1.2.
Severity: 4.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 17, 2025, 5:15 p.m. | 54 minutes ago
Description : CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with access to a Thorium cluster could impersonate the Elasticsearch service. Fixed in 1.1.2.
Severity: 4.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...