boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-23368HIGH
wildfly-core — Org.wildfly.core:wildfly-elytron-integration: wildfly elytron brute force attack via cli
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0085   55.4     —
AFFECTED
  Product                                                           Versions     Fixed
  wildfly-core                                                      unspecified  —
  Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7  unspecified  0:7.3.18-3.GA_redhat_00001.1.el7eap
  Red Hat JBoss Enterprise Application Platform 8.1                 unspecified  —
  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8      unspecified  0:8.1.6-5.GA_redhat_00007.1.el8eap
  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9      unspecified  0:8.1.6-5.GA_redhat_00007.1.el9eap
  Red Hat Build of Keycloak                                         unspecified  —
  Red Hat Data Grid 8                                               unspecified  —
  Red Hat Fuse 7                                                    unspecified  —
  Red Hat Fuse 7                                                    unspecified  —
  Red Hat Integration Camel K 1                                     unspecified  —
  + 7 more
TIMELINE
  Jan 14  Reserved by redhat
  Mar 4   Published (CNA: redhat)
  Aug 17  EXPLOIT PUBLISHED — CVE-2025-23368 (wildfly-core). Public exploit reference added.
CWE-307 · CNA: redhat · CVSS v3.1 · 7 references · NVD status: Modified

Description

A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
January 14, 2025ReservedReserved by redhat
March 4, 2025PublishedPublished (CNA: redhat)
August 17, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2025-23368 (wildfly-core). Public exploit reference added.

Affected

Affected products and packages — 17 rows
VendorProduct / PackageEcosystemVersion introducedFixed
wildfly-core
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 70:7.3.18-3.GA_redhat_00001.1.el7eap
Red HatRed Hat JBoss Enterprise Application Platform 8.1
Red HatRed Hat JBoss Enterprise Application Platform 8.1 for RHEL 80:8.1.6-5.GA_redhat_00007.1.el8eap
Red HatRed Hat JBoss Enterprise Application Platform 8.1 for RHEL 90:8.1.6-5.GA_redhat_00007.1.el9eap
Red HatRed Hat Build of Keycloak
Red HatRed Hat Data Grid 8
Red HatRed Hat Fuse 7
Red HatRed Hat Fuse 7
Red HatRed Hat Integration Camel K 1
Red HatRed Hat JBoss Data Grid 7
Red HatRed Hat JBoss Enterprise Application Platform 7
Red HatRed Hat JBoss Enterprise Application Platform Expansion Pack
Red HatRed Hat Process Automation 7
Red HatRed Hat Process Automation 7
Red HatRed Hat Single Sign-On 7
Red HatRed Hat Single Sign-On 7

Weaknesses

CWE-307

References (7)

Related

Authoritative record: CVE-2025-23368 at cve.org

Vendors: red hat

Weaknesses: CWE-307

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-23368 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.