CVE-2013-3300

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
29/07/2013
Last modified:
11/04/2025

Description

The JsonParser class in json/JsonParser.scala in Lift before 2.5 interprets a certain end-index value as a length value, which allows remote authenticated users to obtain sensitive information from other users' sessions via invalid input data containing a

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:liftweb:lift:*:rc6:*:*:*:*:*:* 2.5 (including)
cpe:2.3:a:liftweb:lift:2.1:*:*:*:*:*:*:*
cpe:2.3:a:liftweb:lift:2.2:*:*:*:*:*:*:*
cpe:2.3:a:liftweb:lift:2.3:*:*:*:*:*:*:*
cpe:2.3:a:liftweb:lift:2.4:*:*:*:*:*:*:*
cpe:2.3:a:liftweb:lift:2.5:m4:*:*:*:*:*:*
cpe:2.3:a:liftweb:lift:2.5:rc1:*:*:*:*:*:*
cpe:2.3:a:liftweb:lift:2.5:rc2:*:*:*:*:*:*
cpe:2.3:a:liftweb:lift:2.5:rc3:*:*:*:*:*:*
cpe:2.3:a:liftweb:lift:2.5:rc4:*:*:*:*:*:*
cpe:2.3:a:liftweb:lift:2.5:rc5:*:*:*:*:*:*