Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-23368

Опубликовано: 03 мар. 2025
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.

Отчет

According to WildFly Elytron, this affects all versions of JBoss EAP from version 7.1. Red Hat build of Keycloak does not ship wildfly-elytron.

Меры по смягчению последствий

The effectiveness of an attack will also be dependent on the complexity of the usernames and passwords defined for the target installation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Keycloakwildfly-elytronNot affected
Red Hat Data Grid 8wildfly-elytronAffected
Red Hat Fuse 7wildfly-elytronNot affected
Red Hat Fuse 7wildfly-elytron-integrationWill not fix
Red Hat Integration Camel K 1wildfly-elytronNot affected
Red Hat JBoss Data Grid 7wildfly-elytronNot affected
Red Hat JBoss Enterprise Application Platform 7wildfly-elytron-integrationWill not fix
Red Hat JBoss Enterprise Application Platform Expansion Packwildfly-elytron-integrationNot affected
Red Hat Process Automation 7wildfly-elytronNot affected
Red Hat Process Automation 7wildfly-elytron-integrationWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-307
https://bugzilla.redhat.com/show_bug.cgi?id=2337621org.wildfly.core:wildfly-elytron-integration: Wildfly Elytron Brute Force Attack via CLI

EPSS

Процентиль: 53%
0.00817
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
больше 1 года назад

A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.

CVSS3: 8.1
github
6 месяцев назад

Wildfly Elytron integration susceptible to brute force attacks via CLI

EPSS

Процентиль: 53%
0.00817
Низкий

8.1 High

CVSS3