{"id":"CVE-2013-3300","aliases":[],"url":"https://o3.security/vulnerability/CVE-2013-3300","summary":"Lift Sensitive Information Disclosure","details":"The JsonParser class in json/JsonParser.scala in Lift before 2.5 interprets a certain end-index value as a length value, which allows remote authenticated users to obtain sensitive information from other users' sessions via invalid input data containing a < (less than) character.","published":"2022-05-17T05:07:19Z","modified":"2025-09-30T19:39:30.217393Z","cvss":null,"epss":{"score":0.01477,"percentile":0.71878,"asOf":"2026-08-22"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Maven","name":"net.liftweb:lift-webkit","fixedVersion":null},{"ecosystem":"Maven","name":"net.liftweb:lift-webkit_2.7.7","fixedVersion":null},{"ecosystem":"Maven","name":"net.liftweb:lift-webkit_2.8.0","fixedVersion":null},{"ecosystem":"Maven","name":"net.liftweb:lift-webkit_2.8.1","fixedVersion":null},{"ecosystem":"Maven","name":"net.liftweb:lift-webkit_2.8.2","fixedVersion":null},{"ecosystem":"Maven","name":"net.liftweb:lift-webkit_2.9.0","fixedVersion":null},{"ecosystem":"Maven","name":"net.liftweb:lift-webkit_2.9.0-1","fixedVersion":null},{"ecosystem":"Maven","name":"net.liftweb:lift-webkit_2.9.1","fixedVersion":"2.5"}],"fix":{"url":"https://github.com/lift/framework/commit/099d9c86cf6d81f4953957add478ab699946e601","label":"lift/framework@099d9c8"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-3300"},{"type":"WEB","url":"https://github.com/lift/framework/commit/099d9c86cf6d81f4953957add478ab699946e601"},{"type":"PACKAGE","url":"https://github.com/lift/framework"},{"type":"WEB","url":"http://blog.addepar.com/2013/07/an-atypical-web-vulnerability.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-09-30T19:39:30.217393Z"}}