VYPR
Medium severity6.1NVD Advisory· Published Jan 2, 2020· Updated Jun 17, 2026

CVE-2019-14862

CVE-2019-14862

Description

There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
knockoutnpm
< 3.5.03.5.0

Affected products

9
  • cpe:2.3:a:knockoutjs:knockout:*:*:*:*:*:*:*:*
    Range: <=3.4.2
  • cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise:*:*:*+ 2 more
    • cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise:*:*:*
    • cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*
    • cpe:2.3:a:oracle:business_intelligence:5.5.0.0.0:*:*:*:enterprise:*:*:*
  • cpe:2.3:a:oracle:goldengate:12.3.0.1.2:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:decision_manager:7.0:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:*
  • ghsa-coords
    Range: < 3.5.0
  • Red Hat/knockoutv5
    Range: all knockout versions before 3.5.0-beta

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.