CVE-2025-23368: Wildfly Elytron integration susceptible to brute force attacks via CLI
A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.
References
- access.redhat.com/security/cve/CVE-2025-23368
- bugzilla.redhat.com/show_bug.cgi?id=2337621
- github.com/advisories/GHSA-qhp6-6p8p-2rqh
- github.com/wildfly/wildfly-core
- github.com/wildfly/wildfly-core/commit/11e873031c522a0b36afb59880ce4dd59efd0bc0
- github.com/wildfly/wildfly-core/commit/a6f9d7534aa44de741337756f8377ad3a81f7695
- github.com/wildfly/wildfly-core/pull/6634
- github.com/wildfly/wildfly-core/pull/6635
- github.com/wildfly/wildfly-core/security/advisories/GHSA-qhp6-6p8p-2rqh
- nvd.nist.gov/vuln/detail/CVE-2025-23368
- www.gruppotim.it/it/footer/red-team.html
Code Behaviors & Features
Detect and mitigate CVE-2025-23368 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →