Information Exposure Affecting net.liftweb:lift-json_2.9.1 package, versions [,2.5-RC3)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.14% (50th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-NETLIFTWEB-30460
  • published8 Jun 2016
  • disclosed29 Jul 2013
  • creditUnknown

Introduced: 29 Jul 2013

CVE-2013-3300  (opens in a new tab)
CWE-119  (opens in a new tab)

Overview

net.liftweb:lift-json_2.9.1 The JsonParser class in json/JsonParser.scala in Lift before 2.5 interprets a certain end-index value as a length value, which allows remote authenticated users to obtain sensitive information from other users' sessions via invalid input data containing a < (less than) character.

References

CVSS Scores

version 3.1