CVE-2013-3300
29.07.2013, 13:59
The JsonParser class in json/JsonParser.scala in Lift before 2.5 interprets a certain end-index value as a length value, which allows remote authenticated users to obtain sensitive information from other users' sessions via invalid input data containing a < (less than) character.Enginsight
Vendor | Product | Version |
---|---|---|
liftweb | lift | 𝑥 ≤ 2.5 |
liftweb | lift | 2.1 |
liftweb | lift | 2.2 |
liftweb | lift | 2.3 |
liftweb | lift | 2.4 |
liftweb | lift | 2.5:m4 |
liftweb | lift | 2.5:rc1 |
liftweb | lift | 2.5:rc2 |
liftweb | lift | 2.5:rc3 |
liftweb | lift | 2.5:rc4 |
liftweb | lift | 2.5:rc5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References