ZeroHour

CVE-2019-14862

PoC
CVSS 3.1
6.1 medium
EPSS
2%p80
Published
()
Modified
Description

There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

Vendors
knockoutjsredhatoracle
Products
knockout, decision manager, process automation, business intelligence, goldengate
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.