CVE-2025-3019
published 2025-03-31CVE-2025-3019: KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a malicious link or opens a malicious web…
PriorityP339high7.2CVSS 3.1
AVNACLPRNUINSCCLILAN
EPSS
0.26%
17.8th percentile
KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a malicious link or opens a malicious web page, arbitrary Java Script may be executed with this user's permissions. This can lead to information loss and/or modification of existing data.
The issues are caused by a bug https://github.com/Baroshem/nuxt-security/issues/610 in the widely used nuxt-security module.
There are no viable workarounds therefore we strongly recommend to update to one of the following versions of KNIME Business Hub:
* 1.13.3 or later
* 1.12.4 or later
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| knime | business_hub | < 1.12.4 | 1.12.4 |
| knime | business_hub | >= 1.13.0 < 1.13.3 | 1.13.3 |
| knime | knime_business_hub | >= 1.12.0 < 1.12.4 | 1.12.4 |
| knime | knime_business_hub | >= 1.13.0 < 1.13.3 | 1.13.3 |
| msrc | cbl2_qemu_6.2.0-23_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_qemu_6.2.0-24_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:M/U:Amber
vendor_msrc6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4c3m-33r2-8r8w: KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages
ghsa_unreviewed·2025-03-31
CVE-2025-3019 [MEDIUM] CWE-79 GHSA-4c3m-33r2-8r8w: KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages
KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a malicious link or opens a malicious web page, arbitrary Java Script may be executed with this user's permissions. This can lead to information loss and/or modification of existing data.
The issues are caused by a bug https://github.com/Baroshem/nuxt-security/issues/610 in the widely used nuxt-security module.
There are no viable workarounds therefore we strongly recommend to update to one of the following versions of KNIME Business Hub:
* 1.13.3 or later
* 1.12.4 or later
Microsoft
Qemu: e1000e: heap use-after-free in e1000e_write_packet_to_guest()
vendor_msrc·2023-07-11·CVSS 6.0
CVE-2023-3019 [MEDIUM] CWE-416 Qemu: e1000e: heap use-after-free in e1000e_write_packet_to_guest()
Qemu: e1000e: heap use-after-free in e1000e_write_packet_to_guest()
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference:
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-31
Published