{"id":"CVE-2025-23368","aliases":["GHSA-qhp6-6p8p-2rqh"],"url":"https://o3.security/vulnerability/CVE-2025-23368","summary":"Org.wildfly.core:wildfly-elytron-integration: wildfly elytron brute force attack via cli","details":"### Impact\n\nA flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.\n\n### Patches\n\nThe default behaviour has been changed in WildFly Core 31.0.3.Final, and 32.0.0.Beta3 - the first version is used by WildFly 39.0.1.Final and the second will be included in WildFly 40.\n\n### Workarounds\n\nNo direct workaround.\nMonitoring network traffic / blocking suspicious traffic may help.\n\n### References\n\nhttps://www.cve.org/CVERecord?id=CVE-2025-23368\nhttps://issues.redhat.com/browse/WFCORE-7192\n\n### Acknowledgements\n\nWe would like to thank Claudia Bartolini (TIM S.p.A), Marco Ventura (TIM S.p.A), and Massimiliano Brolli (TIM S.p.A) for reporting this issue.","published":"2025-03-04T15:14:47.806Z","modified":"2026-09-16T03:30:51.952607811Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.wildfly.core:wildfly-elytron-integration","fixedVersion":"32.0.0.Beta3"},{"ecosystem":"Maven","name":"org.wildfly.core:wildfly-elytron-integration","fixedVersion":"31.0.3.Final"}],"fix":{"url":"https://github.com/wildfly/wildfly-core/pull/6634","label":"wildfly/wildfly-core#6634"},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html"},{"type":"WEB","url":"https://www.gruppotim.it/it/footer/red-team.html"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:18054"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:18055"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:18059"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:33371"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2025-23368"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/23xxx/CVE-2025-23368.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-23368"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2337621"},{"type":"PACKAGE","url":"https://github.com/wildfly/wildfly-core"},{"type":"WEB","url":"https://github.com/wildfly/wildfly-core/security/advisories/GHSA-qhp6-6p8p-2rqh"},{"type":"WEB","url":"https://github.com/wildfly/wildfly-core/pull/6634"},{"type":"WEB","url":"https://github.com/wildfly/wildfly-core/pull/6635"},{"type":"WEB","url":"https://github.com/wildfly/wildfly-core/commit/11e873031c522a0b36afb59880ce4dd59efd0bc0"},{"type":"WEB","url":"https://github.com/wildfly/wildfly-core/commit/a6f9d7534aa44de741337756f8377ad3a81f7695"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-16T03:30:51.952607811Z"}}