Information Exposure Affecting net.liftweb:lift-json_2.9.1 package, versions [,2.5-RC3)


0.0
medium

Snyk CVSS

    Attack Complexity Low
NVD  medium

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-JAVA-NETLIFTWEB-30460
  • published 8 Jun 2016
  • disclosed 29 Jul 2013
  • credit Unknown

Overview

net.liftweb:lift-json_2.9.1 The JsonParser class in json/JsonParser.scala in Lift before 2.5 interprets a certain end-index value as a length value, which allows remote authenticated users to obtain sensitive information from other users' sessions via invalid input data containing a < (less than) character.

References