CVE-2025-23368
published 2025-03-04CVE-2025-23368: A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within…
PriorityP344high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.82%
53.0th percentile
A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | data_grid | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | wildfly_core | < 31.0.3 | 31.0.3 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa8.1HIGH
osv8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Wildfly Elytron integration susceptible to brute force attacks via CLI
ghsa·2026-02-13·CVSS 8.1
CVE-2025-23368 [HIGH] CWE-307 Wildfly Elytron integration susceptible to brute force attacks via CLI
Wildfly Elytron integration susceptible to brute force attacks via CLI
### Impact
A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.
### Patches
The default behaviour has been changed in WildFly Core 31.0.3.Final, and 32.0.0.Beta3 - the first version is used by WildFly 39.0.1.Final and the second will be included in WildFly 40.
### Workarounds
No direct workaround.
Monitoring network traffic / blocking suspicious traffic may help.
### References
https://www.cve.org/CVERecord?id=CVE-2025-23368
https://issues.redhat.com/browse/WFCORE-7192
### Acknowledgements
We would like to thank Claudia Bartoli
OSV
Wildfly Elytron integration susceptible to brute force attacks via CLI
osv·2026-02-13·CVSS 8.1
CVE-2025-23368 [HIGH] Wildfly Elytron integration susceptible to brute force attacks via CLI
Wildfly Elytron integration susceptible to brute force attacks via CLI
### Impact
A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.
### Patches
The default behaviour has been changed in WildFly Core 31.0.3.Final, and 32.0.0.Beta3 - the first version is used by WildFly 39.0.1.Final and the second will be included in WildFly 40.
### Workarounds
No direct workaround.
Monitoring network traffic / blocking suspicious traffic may help.
### References
https://www.cve.org/CVERecord?id=CVE-2025-23368
https://issues.redhat.com/browse/WFCORE-7192
### Acknowledgements
We would like to thank Claudia Bartoli
OSV
Duplicate Advisory: Wildfly Elytron integration susceptible to brute force attacks via CLI
osv·2025-03-04
CVE-2025-23368 [HIGH] Duplicate Advisory: Wildfly Elytron integration susceptible to brute force attacks via CLI
Duplicate Advisory: Wildfly Elytron integration susceptible to brute force attacks via CLI
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-qhp6-6p8p-2rqh. This link is maintained to preserve external references.
### Original Description
A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.
Red Hat
org.wildfly.core:wildfly-elytron-integration: Wildfly Elytron Brute Force Attack via CLI
vendor_redhat·2025-03-03·CVSS 8.1
CVE-2025-23368 [HIGH] CWE-307 org.wildfly.core:wildfly-elytron-integration: Wildfly Elytron Brute Force Attack via CLI
org.wildfly.core:wildfly-elytron-integration: Wildfly Elytron Brute Force Attack via CLI
A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.
A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.
Statement: According to WildFly Elytron, this affects all versions of JBoss EAP from version 7.1.
Red Hat build of Keycloak does not ship wildfly-elytron.
Mitigation: The effectiveness of an attack will also be dependent on the c
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2026:18054https://access.redhat.com/errata/RHSA-2026:18055https://access.redhat.com/errata/RHSA-2026:18059https://access.redhat.com/errata/RHSA-2026:33371https://access.redhat.com/security/cve/CVE-2025-23368https://bugzilla.redhat.com/show_bug.cgi?id=2337621https://www.gruppotim.it/it/footer/red-team.html
2025-03-04
Published