CVE-2019-14862
published 2020-01-02CVE-2019-14862: There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to…
PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
2.06%
79.2th percentile
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-knockout | < node-knockout 3.4.2-3 (bookworm) | node-knockout 3.4.2-3 (bookworm) |
| knockoutjs | knockout | <= 3.4.2 | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | goldengate | — | — |
| red_hat | knockout | — | — |
| red_hat | knockout | >= 0 < 3.5.0 | 3.5.0 |
| redhat | decision_manager | — | — |
| redhat | process_automation | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1LOW
vendor_oracle6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
XSS in knockout
osv·2020-04-01
CVE-2019-14862 [MEDIUM] XSS in knockout
XSS in knockout
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
GHSA
XSS in knockout
ghsa·2020-04-01
CVE-2019-14862 [MEDIUM] CWE-79 XSS in knockout
XSS in knockout
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
OSV
CVE-2019-14862: There is a vulnerability in knockout before version 3
osv·2020-01-02·CVSS 6.1
CVE-2019-14862 [MEDIUM] CVE-2019-14862: There is a vulnerability in knockout before version 3
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
Oracle
Oracle Oracle GoldenGate Risk Matrix: Internal Framework (Knockout) — CVE-2019-14862
vendor_oracle·2022-04-15·CVSS 6.1
CVE-2019-14862 [MEDIUM] Oracle Oracle GoldenGate Risk Matrix: Internal Framework (Knockout) — CVE-2019-14862
Oracle Oracle GoldenGate Risk Matrix: Internal Framework (Knockout) vulnerability
CVE: CVE-2019-14862
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Analytics Server (Knockout) — CVE-2019-14862
vendor_oracle·2021-01-15·CVSS 6.1
CVE-2019-14862 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Analytics Server (Knockout) — CVE-2019-14862
Oracle Oracle Fusion Middleware Risk Matrix: Analytics Server (Knockout) vulnerability
CVE: CVE-2019-14862
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: BI Platform Security (Knockout) — CVE-2019-14862
vendor_oracle·2020-07-15·CVSS 6.1
CVE-2019-14862 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: BI Platform Security (Knockout) — CVE-2019-14862
Oracle Oracle Fusion Middleware Risk Matrix: BI Platform Security (Knockout) vulnerability
CVE: CVE-2019-14862
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Red Hat
knockout: Cross-site Scripting (XSS) attacks due to not escaping the name attribute.
vendor_redhat·2019-10-15·CVSS 6.1
CVE-2019-14862 [MEDIUM] CWE-79 knockout: Cross-site Scripting (XSS) attacks due to not escaping the name attribute.
knockout: Cross-site Scripting (XSS) attacks due to not escaping the name attribute.
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
Debian
CVE-2019-14862: node-knockout - There is a vulnerability in knockout before version 3.5.0-beta, where after esca...
vendor_debian·2019·CVSS 6.1
CVE-2019-14862 [MEDIUM] CVE-2019-14862: node-knockout - There is a vulnerability in knockout before version 3.5.0-beta, where after esca...
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
Scope: local
bookworm: resolved (fixed in 3.4.2-3)
bullseye: resolved (fixed in 3.4.2-3)
forky: resolved (fixed in 3.4.2-3)
sid: resolved (fixed in 3.4.2-3)
trixie: resolved (fixed in 3.4.2-3)
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14862https://snyk.io/vuln/npm:knockout:20180213https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14862https://snyk.io/vuln/npm:knockout:20180213https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.html
2020-01-02
Published