CVE-2019-14862

NameCVE-2019-14862
DescriptionThere is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs943560

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-knockout (PTS)buster3.4.2-2+deb10u1fixed
bullseye3.5.1-1fixed
sid, trixie, bookworm3.5.1+ds-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-knockoutsourcebuster3.4.2-2+deb10u1
node-knockoutsource(unstable)3.4.2-3unimportant943560

Notes

https://github.com/knockout/knockout/issues/1244
https://github.com/knockout/knockout/pull/2345
https://github.com/knockout/knockout/commit/7e280b2b8a04cc19176b5171263a5c68bda98efb
Only impacts browsers which are totally insecure and EOLed anyway

Search for package or bug name: Reporting problems