Описание
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| node-knockout | fixed | 3.4.2-3 | package | |
| node-knockout | fixed | 3.4.2-2+deb10u1 | buster | package |
Примечания
https://github.com/knockout/knockout/issues/1244
https://github.com/knockout/knockout/pull/2345
https://github.com/knockout/knockout/commit/7e280b2b8a04cc19176b5171263a5c68bda98efb
Only impacts browsers which are totally insecure and EOLed anyway
Связанные уязвимости
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
Уязвимость библиотеки Knockout.js, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю осуществить межсайтовую сценарную атаку