Description

A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.

INFO

Published Date :

2025-03-04T15:14:47.806Z

Last Modified :

2026-03-10T18:48:10.400Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2025-23368 vulnerability.

Vendors Products
Redhat
  • Build Keycloak
  • Data Grid
  • Integration
  • Jboss Data Grid
  • Jboss Enterprise Application Platform
  • Jboss Enterprise Bpms Platform
  • Jboss Fuse
  • Jbosseapxp
  • Red Hat Single Sign On
  • Wildfly Core

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact