Candidate: CVE-2019-14862 PublicDate: 2020-01-02 15:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14862 https://github.com/knockout/knockout/issues/1244 https://github.com/knockout/knockout/pull/2345 https://github.com/knockout/knockout/commit/7e280b2b8a04cc19176b5171263a5c68bda98efb Description: There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_node-knockout: upstream_node-knockout: needs-triage precise/esm_node-knockout: DNE trusty_node-knockout: ignored (out of standard support) trusty/esm_node-knockout: DNE xenial_node-knockout: DNE bionic_node-knockout: DNE disco_node-knockout: ignored (reached end-of-life) eoan_node-knockout: ignored (reached end-of-life) focal_node-knockout: not-affected (3.4.2-3) devel_node-knockout: not-affected (3.4.2-3)