Description
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
Recommendation
Update the knockout package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.5.0
- Patched version(s): 3.5.0
References
- GHSA-vcjj-xf2r-mwvc
- bugzilla.redhat.com
- snyk.io
- www.oracle.com
- www.whitesourcesoftware.com
- CVE-2019-14862
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- hexo-admin plugin for Node.js XSS Vulnerability - CVE-2019-17606
- XSS in dojox due to insufficient escape in dojox.xmpp.util.xmlEncode - CVE-2019-10785
- XSS in jQuery as used in Drupal, Backdrop CMS, and other products - CVE-2019-11358
- XSS in TinyMCE - CVE-2019-1010091
You might also like:
- Tags:
- npm
- knockout
Anything's wrong? Let us know Last updated on February 01, 2023


