Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3jxr-23ph-c89g

Опубликовано: 04 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Wildfly Elytron integration susceptible to brute force attacks via CLI

A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.

Пакеты

Наименование

org.wildfly.core:wildfly-elytron-integration

maven
Затронутые версииВерсия исправления

<= 27.0.0.Final

Отсутствует

EPSS

Процентиль: 30%
0.00108
Низкий

8.1 High

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 8.1
redhat
7 месяцев назад

A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.

CVSS3: 8.1
nvd
6 месяцев назад

A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.

EPSS

Процентиль: 30%
0.00108
Низкий

8.1 High

CVSS3

Дефекты

CWE-307