CVE-2025-35431

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
17/09/2025
Last modified:
18/09/2025

Description

CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify LDAP authorization data such as group memberships. Fixed in 1.1.1.