CVE-2019-14862: Knockoutjs Knockout
Medium severity, CVSS 6.1. EPSS: 2.1% chance of exploitation in the next 30 days.
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
Affected products
- Knockoutjs Knockout: up to and including 3.4.2
- Oracle Business Intelligence: version 5.5.0.0.0 only; version 12.2.1.3.0 only; version 12.2.1.4.0 only
- Oracle Goldengate: version 12.3.0.1.2 only
- Red Hat Decision Manager: version 7.0 only
- Red Hat Process Automation: version 7.0 only
Published 2020-01-02. Last modified 2026-06-17.