{"id":"GHSA-qfmr-6qvh-49gm","summary":"XSS","details":"**Withdrawn:** Duplicate of GHSA-vcjj-xf2r-mwvc.\n\nKnockout, before 3.5.0-beta, has an XSS injection point in attr name binding for browser IE7 and older.","modified":"2021-02-25T01:44:38Z","published":"2021-02-25T01:44:38Z","withdrawn":"2021-02-25T01:44:38Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2019-05-22T15:03:20Z","nvd_published_at":null,"cwe_ids":[]},"references":[{"type":"WEB","url":"https://github.com/knockout/knockout/issues/1244"},{"type":"WEB","url":"https://github.com/knockout/knockout/commit/86b06aa8633f9f72b953f512df7471a22689ea14"}],"affected":[{"package":{"name":"knockout","ecosystem":"npm","purl":"pkg:npm/knockout"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.5.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-qfmr-6qvh-49gm/GHSA-qfmr-6qvh-49gm.json"}}],"schema_version":"1.9.0"}