CVE-2025-3019 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a malicious link or opens a malicious web p…
Medium CVSS: 5.3

CVE-2025-3019

KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a malicious link or opens a malicious web page, arbitrary Java Script may be executed with this user's permissions. This can lead to information loss and/or modification of existing data.
The issues are caused by a bug https://github.com/Baroshem/nuxt-security/issues/610 in the widely used nuxt-security module.





There are no viable workarounds therefore we strongly recommend to update to one of the following versions of KNIME Business Hub:





* 1.13.3 or later






* 1.12.4 or later
Vendor
Knime
Product
Business Hub
CWE
CWE-79
Yayın Tarihi
2025-03-31 07:15:19
Güncelleme
2025-10-08 17:18:01
Source Identifier
security@knime.com
KEV Date Added
-

Kategoriler

Referanslar