WildFly Elytron Brute Force Attack Vulnerability via CLI

Vulnerability

A vulnerability exists in the WildFly Elytron integration, where the component fails to adequately limit repeated authentication failures within a short period. This shortcoming increases the risk of brute force attacks through the Command Line Interface (CLI). The vulnerability can be exploited over the network on any WildFly or JBoss EAP ports that require HTTP or SASL authentication.

Impact

Exploitation of this vulnerability could lead to successful brute force attacks, allowing attackers to gain unauthorized access by guessing credentials.

Reproduction

The vulnerability can be reproduced by attempting to authenticate repeatedly within a short time frame over a network connection to a WildFly or JBoss EAP port that requires HTTP or SASL authentication. This can be automated with a script or tool that sends multiple authentication requests in quick succession, taking advantage of the lack of proper rate limiting.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
0.6
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.