Medium severity6.1NVD Advisory· Published Jan 2, 2020· Updated Jun 17, 2026
CVE-2019-14862
CVE-2019-14862
Description
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
knockoutnpm | < 3.5.0 | 3.5.0 |
Affected products
9cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise:*:*:*+ 2 more
- cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise:*:*:*
- cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*
- cpe:2.3:a:oracle:business_intelligence:5.5.0.0.0:*:*:*:enterprise:*:*:*
- cpe:2.3:a:oracle:goldengate:12.3.0.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:decision_manager:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:*
- Red Hat/knockoutv5Range: all knockout versions before 3.5.0-beta
Patches
Vulnerability mechanics
References
11- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujan2021.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujul2020.htmlnvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/npm:knockout:20180213nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-vcjj-xf2r-mwvcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-14862ghsaADVISORY
- github.com/knockout/knockout/commit/7e280b2b8a04cc19176b5171263a5c68bda98efbghsaWEB
- github.com/knockout/knockout/issues/1244ghsaWEB
- github.com/knockout/knockout/pull/2345ghsaWEB
- www.whitesourcesoftware.com/vulnerability-database/WS-2019-0015ghsaWEB
News mentions
0No linked articles in our index yet.