CVE-2013-3300: Liftweb Lift
Medium severity, CVSS 4.0. EPSS: 1.5% chance of exploitation in the next 30 days.
The JsonParser class in json/JsonParser.scala in Lift before 2.5 interprets a certain end-index value as a length value, which allows remote authenticated users to obtain sensitive information from other users' sessions via invalid input data containing a < (less than) character.
Affected products
- Liftweb Lift: up to and including 2.5; version 2.1 only; version 2.2 only; version 2.3 only; version 2.4 only; version 2.5 only
Published 2013-07-29. Last modified 2026-06-16.