{"id":"CVE-2025-23368","title":"A flaw was found in Wildfly Elytron integration","summary":"A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-307"],"vendor":"redhat","product":"wildfly_core","affected":["wildfly_core < 31.0.3","data_grid = 8.0","jboss_enterprise_application_platform = 7.0.0","jboss_enterprise_application_platform = 8.0.0"],"patched":["wildfly_core 31.0.3"],"published":"2025-03-04","updated":"2026-09-14","sourceUpdated":"2026-09-14T22:16:55.233","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-23368","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:18054","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:18055","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:18059","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:33371","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-23368","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2337621","label":"secalert@redhat.com"},{"url":"https://www.gruppotim.it/it/footer/red-team.html","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-23368.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-23368"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-23368"}],"tags":["nvd","csaf","vex","red-hat","cve.org"],"epss":0.00867,"epssPercentile":0.57194,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2025-03-04T15:57:14.702481Z"},"ingestedAt":"2026-06-30T03:49:03.444Z","slug":"CVE-2025-23368","body":"## Overview\n\nA flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.\n\n## Affected\n\n- `wildfly_core < 31.0.3`\n- `data_grid = 8.0`\n- `jboss_enterprise_application_platform = 7.0.0`\n- `jboss_enterprise_application_platform = 8.0.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `wildfly_core 31.0.3`\n\n## Vendor advisories\n\n- **RHSA-2026:33371** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server · released 2026-06-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:33371)\n- **RHSA-2026:18054** · Red Hat · fixed in: Red Hat JBoss EAP 8.1 for RHEL 8 · released 2026-05-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:18054)\n- **RHSA-2026:18055** · Red Hat · fixed in: Red Hat JBoss EAP 8.1 for RHEL 9 · released 2026-05-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:18055)\n- **RHSA-2026:18059** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 8.1 · released 2026-05-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:18059)\n- **Red Hat VEX** · Important · affected: Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Process Automation 7, Red Hat Single Sign-On 7 · no fix planned: Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Process Automation 7, Red Hat Single Sign-On 7, … · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-23368.json)","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}