{"id":"CVE-2013-3300","aliases":[],"url":"https://o3.security/vulnerability/CVE-2013-3300","summary":"The JsonParser class in json/JsonParser.scala in Lift before 2.5 interprets a certain end-index value as a length value, which allows remote authenticated users to obtain sensitive…","details":"The JsonParser class in json/JsonParser.scala in Lift before 2.5 interprets a certain end-index value as a length value, which allows remote authenticated users to obtain sensitive information from other users' sessions via invalid input data containing a < (less than) character.","published":"2013-07-29T13:59:05.480","modified":"2026-06-16T23:54:51.000","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[],"fix":{"url":"https://github.com/lift/framework/commit/099d9c86cf6d81f4953957add478ab699946e601","label":"lift/framework@099d9c8"},"references":[{"type":"EXPLOIT","url":"http://blog.addepar.com/2013/07/an-atypical-web-vulnerability.html"},{"type":"EXPLOIT","url":"https://github.com/lift/framework/commit/099d9c86cf6d81f4953957add478ab699946e601"},{"type":"EXPLOIT","url":"http://blog.addepar.com/2013/07/an-atypical-web-vulnerability.html"},{"type":"EXPLOIT","url":"https://github.com/lift/framework/commit/099d9c86cf6d81f4953957add478ab699946e601"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-16T23:54:51.000"}}