OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKilda which in combination with GHSL-2025-024 allows unauthenticated attackers to exfiltrate information from the instance where the OpenKilda UI is running. This issue may lead to Information disclosure. This issue has been patched in version 1.164.0.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Telstra
Telstra openkilda |
|
| Vendors & Products |
Telstra
Telstra openkilda |
Mon, 11 Aug 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKilda which in combination with GHSL-2025-024 allows unauthenticated attackers to exfiltrate information from the instance where the OpenKilda UI is running. This issue may lead to Information disclosure. This issue has been patched in version 1.164.0. | |
| Title | OpenKilda XXE in SAML configuration | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-11T21:34:48.750Z
Updated: 2025-08-12T15:44:24.225Z
Reserved: 2025-08-04T17:34:24.420Z
Link: CVE-2025-54992
Updated: 2025-08-12T15:44:20.844Z
Status : Awaiting Analysis
Published: 2025-08-11T22:15:27.693
Modified: 2025-08-12T14:25:33.177
Link: CVE-2025-54992
No data.