OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKilda which in combination with GHSL-2025-024 allows unauthenticated attackers to exfiltrate information from the instance where the OpenKilda UI is running. This issue may lead to Information disclosure. This issue has been patched in version 1.164.0.
History

Tue, 12 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 Aug 2025 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Telstra
Telstra openkilda
Vendors & Products Telstra
Telstra openkilda

Mon, 11 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
Description OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKilda which in combination with GHSL-2025-024 allows unauthenticated attackers to exfiltrate information from the instance where the OpenKilda UI is running. This issue may lead to Information disclosure. This issue has been patched in version 1.164.0.
Title OpenKilda XXE in SAML configuration
Weaknesses CWE-611
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-08-11T21:34:48.750Z

Updated: 2025-08-12T15:44:24.225Z

Reserved: 2025-08-04T17:34:24.420Z

Link: CVE-2025-54992

cve-icon Vulnrichment

Updated: 2025-08-12T15:44:20.844Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-11T22:15:27.693

Modified: 2025-08-12T14:25:33.177

Link: CVE-2025-54992

cve-icon Redhat

No data.