Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-23368

Опубликовано: 03 мар. 2025
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.

Отчет

According to WildFly Elytron, this affects all versions of JBoss EAP from version 7.1. Red Hat build of Keycloak does not ship wildfly-elytron.

Меры по смягчению последствий

The effectiveness of an attack will also be dependent on the complexity of the usernames and passwords defined for the target installation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Keycloakorg.wildfly.security/wildfly-elytronNot affected
Red Hat Data Grid 8org.wildfly.security/wildfly-elytronAffected
Red Hat Fuse 7org.wildfly.security/wildfly-elytronOut of support scope
Red Hat Integration Camel K 1org.wildfly.security/wildfly-elytronWill not fix
Red Hat JBoss Data Grid 7org.wildfly.security/wildfly-elytronOut of support scope
Red Hat JBoss Enterprise Application Platform 7wildfly-elytronAffected
Red Hat JBoss Enterprise Application Platform 8wildfly-elytronAffected
Red Hat JBoss Enterprise Application Platform Expansion Packwildfly-elytronNot affected
Red Hat Process Automation 7org.wildfly.security/wildfly-elytronOut of support scope
Red Hat Single Sign-On 7org.wildfly.security/wildfly-elytronOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-307
https://bugzilla.redhat.com/show_bug.cgi?id=2337621org.wildfly.core:wildfly-elytron-integration: Wildfly Elytron Brute Force Attack via CLI

EPSS

Процентиль: 30%
0.00108
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
6 месяцев назад

A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.

CVSS3: 8.1
github
6 месяцев назад

Wildfly Elytron integration susceptible to brute force attacks via CLI

EPSS

Процентиль: 30%
0.00108
Низкий

8.1 High

CVSS3