CVE-2019-14862
02.01.2020, 15:15
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
| Vendor | Product | Version |
|---|---|---|
| knockoutjs | knockout | 𝑥 ≤ 3.4.2 |
| redhat | decision_manager | 7.0 |
| redhat | process_automation | 7.0 |
| oracle | business_intelligence | 5.5.0.0.0 |
| oracle | business_intelligence | 12.2.1.3.0 |
| oracle | business_intelligence | 12.2.1.4.0 |
| oracle | goldengate | 12.3.0.1.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References