CVE-2019-14862: Knockoutjs Knockout

Medium severity, CVSS 6.1. EPSS: 2.1% chance of exploitation in the next 30 days.

There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

Affected products

  • Knockoutjs Knockout: up to and including 3.4.2
  • Oracle Business Intelligence: version 5.5.0.0.0 only; version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Goldengate: version 12.3.0.1.2 only
  • Red Hat Decision Manager: version 7.0 only
  • Red Hat Process Automation: version 7.0 only

Published 2020-01-02. Last modified 2026-06-17.