CISA Thorium Insufficient Session Expiration Vulnerability

Vulnerability

A vulnerability exists in CISA Thorium versions 1.0.0 prior to 1.1.1, where the application fails to properly invalidate previously used tokens during password resets. This oversight allows an attacker with access to a prior token to log in even after the password has been changed. The issue has been addressed in version 1.1.1.

Impact

Exploitation of this vulnerability allows for unauthorized access to user accounts by reusing old tokens, potentially leading to unauthorized actions or access to sensitive information.

Reproduction

To reproduce this vulnerability, reset a user's password in an LDAP-enabled Thorium cluster. After the reset, attempt to log in using a token that was issued before the password was changed. The login should be successful, indicating that the old token was not properly invalidated.

Remediation

Users can update to CISA Thorium version 1.1.1 or later, where this vulnerability has been fixed.

Added: Sep 17, 2025, 5:23 PM
Updated: Sep 17, 2025, 5:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
6.3
remediation
0.0
relevance
0.5
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.