cbcvebase.
CVE-2019-14862
published 2020-01-02

CVE-2019-14862: There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to…

PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
2.06%
79.2th percentile
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiannode-knockout< node-knockout 3.4.2-3 (bookworm)node-knockout 3.4.2-3 (bookworm)
knockoutjsknockout<= 3.4.2
oraclebusiness_intelligence
oraclebusiness_intelligence
oraclebusiness_intelligence
oraclegoldengate
red_hatknockout
red_hatknockout>= 0 < 3.5.03.5.0
redhatdecision_manager
redhatprocess_automation

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1LOW
vendor_oracle6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.