GHSA-jf9v-fxfq-wm76
Dashboard / Vulnerabilities / GHSA-jf9v-fxfq-wm76
Summary: Lift Sensitive Information Disclosure
Details: The JsonParser class in json/JsonParser.scala in Lift before 2.5 interprets a certain end-index value as a length value, which allows remote authenticated users to obtain sensitive information from other users' sessions via invalid input data containing a < (less than) character.
References: https://nvd.nist.gov/vuln/detail/CVE-2013-3300, https://github.com/lift/framework/commit/099d9c86cf6d81f4953957add478ab699946e601, https://github.com/lift/framework, http://blog.addepar.com/2013/07/an-atypical-web-vulnerability.html
Affected packages
Package
Name: net.liftweb:lift-webkit
Purl: pkg:maven/net.liftweb/lift-webkit
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
Affected versions
0.10
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
