OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKilda which in combination with GHSL-2025-024 allows unauthenticated attackers to exfiltrate information from the instance where the OpenKilda UI is running. This issue may lead to Information disclosure. This issue has been patched in version 1.164.0.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Aug 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 12 Aug 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Telstra
Telstra openkilda |
|
Vendors & Products |
Telstra
Telstra openkilda |
Mon, 11 Aug 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKilda which in combination with GHSL-2025-024 allows unauthenticated attackers to exfiltrate information from the instance where the OpenKilda UI is running. This issue may lead to Information disclosure. This issue has been patched in version 1.164.0. | |
Title | OpenKilda XXE in SAML configuration | |
Weaknesses | CWE-611 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-11T21:34:48.750Z
Updated: 2025-08-12T15:44:24.225Z
Reserved: 2025-08-04T17:34:24.420Z
Link: CVE-2025-54992

Updated: 2025-08-12T15:44:20.844Z

Status : Awaiting Analysis
Published: 2025-08-11T22:15:27.693
Modified: 2025-08-12T14:25:33.177
Link: CVE-2025-54992

No data.