CVE-2025-3019

KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a malicious link or opens a malicious web page, arbitrary Java Script may be executed with this user's permissions. This can lead to information loss and/or modification of existing data. The issues are caused by a bug https://github.com/Baroshem/nuxt-security/issues/610 in the widely used nuxt-security module. There are no viable workarounds therefore we strongly recommend to update to one of the following versions of KNIME Business Hub: * 1.13.3 or later * 1.12.4 or later
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:knime:business_hub:*:*:*:*:*:*:*:*
cpe:2.3:a:knime:business_hub:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-03-31 07:15

Updated : 2025-10-08 17:18


NVD link : CVE-2025-3019

Mitre link : CVE-2025-3019

CVE.ORG link : CVE-2025-3019


JSON object : View

Products Affected

knime

  • business_hub
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')