Description
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-0394 | There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it. |
Github GHSA |
GHSA-vcjj-xf2r-mwvc | XSS in knockout |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T00:26:39.128Z
Reserved: 2019-08-10T00:00:00.000Z
Link: CVE-2019-14862
No data.
Status : Modified
Published: 2020-01-02T15:15:12.100
Modified: 2024-11-21T04:27:31.430
Link: CVE-2019-14862
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA