GHSA-qfmr-6qvh-49gm

Suggest an improvement
Source
https://github.com/advisories/GHSA-qfmr-6qvh-49gm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-qfmr-6qvh-49gm/GHSA-qfmr-6qvh-49gm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qfmr-6qvh-49gm
Withdrawn
2021-02-25T01:44:38Z
Published
2021-02-25T01:44:38Z
Modified
2021-02-25T01:44:38Z
Summary
XSS
Details

Withdrawn: Duplicate of GHSA-vcjj-xf2r-mwvc.

Knockout, before 3.5.0-beta, has an XSS injection point in attr name binding for browser IE7 and older.

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2019-05-22T15:03:20Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / knockout

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.5.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-qfmr-6qvh-49gm/GHSA-qfmr-6qvh-49gm.json"