Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 vulnerability

A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.

Published 4 Mar 2025Updated 14 Sep 202610 sources
CVSS 8.1 ✓ VERIFIED REFERENCE

What happened

A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.

Affected versions

Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7: 0 through * (semver) Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

RepositoryAuthorFirst seenReference
www.gruppotim.itNVD reference2025-03-04Verified