CVE-2025-35431
17.09.2025, 17:15
CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify LDAP authorization data such as group memberships. Fixed in 1.1.1.
| Vendor | Product | Version |
|---|---|---|
| cisa | thorium | 1.0.0 ≤ 𝑥 < 1.1.1 |
𝑥
= Vulnerable software versions
References