CVE-2025-23368
Aliases:GHSA-3jxr-23ph-c89gGHSA-qhp6-6p8p-2rqhGHSA-3JXR-23PH-C89G
Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 04 Mar 2025, 15:14
Last modified:30 Jun 2026, 02:47
Vulnerability Summary
Overall Risk (default)
medium
43/100 CVSS Score
8.1 HIGH
v3.1 (cve.org)
EPSS Score
0.82% LOW
1% probability +0.59%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected
Timeline
04 Mar 2025, 15:14
Published
Vulnerability first disclosed
30 Jun 2026, 02:47
Last Modified
Vulnerability information updated
Description
A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.
CVSS Metrics
- v3.1•HIGH•Score: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.82%• Percentile: 53%
Techniques & Countermeasures
- CWE-307•Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Affected Systems
- org.wildfly.core•wildfly-elytron-integration
≥ 32.0.0.Beta1, < 32.0.0.Beta3 | < 31.0.3.Final | ≤ 27.0.0.Final
- redhat•data_grid
8.0
- redhat•jboss_enterprise_application_platform
7.0.0 | 8.0.0
- redhat•wildfly_core
< 31.0.3
- redhat•wildfly_elytron
na
References (14)
- https://access.redhat.com/security/cve/CVE-2025-23368
- https://bugzilla.redhat.com/show_bug.cgi?id=2337621
- https://www.gruppotim.it/it/footer/red-team.html
- https://nvd.nist.gov/vuln/detail/CVE-2025-23368
- https://github.com/wildfly/wildfly-core
- https://github.com/wildfly/wildfly-core/security/advisories/GHSA-qhp6-6p8p-2rqh
- https://github.com/wildfly/wildfly-core/pull/6634
- https://github.com/wildfly/wildfly-core/pull/6635
- https://github.com/wildfly/wildfly-core/commit/11e873031c522a0b36afb59880ce4dd59efd0bc0
- https://github.com/wildfly/wildfly-core/commit/a6f9d7534aa44de741337756f8377ad3a81f7695
- https://access.redhat.com/errata/RHSA-2026:18059
- https://access.redhat.com/errata/RHSA-2026:18054
- https://access.redhat.com/errata/RHSA-2026:18055
- https://access.redhat.com/errata/RHSA-2026:33371