cbcvebase.
CVE-2019-14862
published 2020-01-02

CVE-2019-14862: There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiannode-knockout< node-knockout 3.4.2-3 (bookworm)node-knockout 3.4.2-3 (bookworm)
knockoutjsknockout<= 3.4.2
oraclebusiness_intelligence
oraclebusiness_intelligence
oraclebusiness_intelligence
oraclegoldengate
red_hatknockout
red_hatknockout>= 0 < 3.5.03.5.0
redhatdecision_manager
redhatprocess_automation

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM