|There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
|CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Vulnerable and fixed packages
The table below lists information on source packages.
|bookworm, sid, trixie
The information below is based on the following data on fixed versions.
Only impacts browsers which are totally insecure and EOLed anyway