CVE-2025-35434: CISA Thorium does not validate TLS connections to Elasticsearch
CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with access to a Thorium cluster could impersonate the Elasticsearch service. Fixed in 1.1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-35434?
CVE-2025-35434 is considered a high severity vulnerability due to its potential for unauthorized access and impersonation of the Elasticsearch service.
How do I fix CVE-2025-35434?
To fix CVE-2025-35434, upgrade to CISA Thorium version 1.1.2 or later.
What impact does CVE-2025-35434 have on my CISA Thorium deployment?
CVE-2025-35434 could allow an attacker to impersonate the Elasticsearch service, potentially leading to data breaches and unauthorized actions within your Thorium cluster.
Is my version of CISA Thorium affected by CVE-2025-35434?
CISA Thorium versions prior to 1.1.2 are affected by CVE-2025-35434 and require upgrading to patch the vulnerability.
Who is affected by CVE-2025-35434?
Organizations using CISA Thorium versions below 1.1.2 that connect to Elasticsearch are at risk from CVE-2025-35434.