CVE-2025-3019

Severity CVSS v4.0:
MEDIUM
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
31/03/2025
Last modified:
08/10/2025

Description

KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a malicious link or opens a malicious web page, arbitrary Java Script may be executed with this user&amp;#39;s permissions. This can lead to information loss and/or modification of existing data.<br /> The issues are caused by a bug https://github.com/Baroshem/nuxt-security/issues/610 in the widely used nuxt-security module.<br /> <br /> <br /> <br /> <br /> <br /> There are no viable workarounds therefore we strongly recommend to update to one of the following versions of KNIME Business Hub:<br /> <br /> <br /> <br /> <br /> <br /> * 1.13.3 or later<br /> <br /> <br /> <br /> <br /> <br /> <br /> * 1.12.4 or later

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:knime:business_hub:*:*:*:*:*:*:*:* 1.12.4 (excluding)
cpe:2.3:a:knime:business_hub:*:*:*:*:*:*:*:* 1.13.0 (including) 1.13.3 (excluding)


References to Advisories, Solutions, and Tools