Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-14862

Опубликовано: 02 янв. 2020
Источник: debian

Описание

There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-knockoutfixed3.4.2-3package
node-knockoutfixed3.4.2-2+deb10u1busterpackage

Примечания

  • https://github.com/knockout/knockout/issues/1244

  • https://github.com/knockout/knockout/pull/2345

  • https://github.com/knockout/knockout/commit/7e280b2b8a04cc19176b5171263a5c68bda98efb

  • Only impacts browsers which are totally insecure and EOLed anyway

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 6 лет назад

There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

CVSS3: 6.1
redhat
больше 6 лет назад

There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

CVSS3: 6.1
nvd
около 6 лет назад

There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

CVSS3: 6.1
github
почти 6 лет назад

XSS in knockout

CVSS3: 6.1
fstec
около 6 лет назад

Уязвимость библиотеки Knockout.js, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю осуществить межсайтовую сценарную атаку