QID 981280

QID 981280: Java (maven) Security Update for com.github.junrar:junrar (GHSA-5xqr-grq4-qwgx)

Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulnerability due to an infinite loop when handling corrupt RAR files.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-5xqr-grq4-qwgx for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981280

    Software Advisories
    Advisory ID Software Component Link
    GHSA-5xqr-grq4-qwgx com.github.junrar:junrar URL Logo github.com/advisories/GHSA-5xqr-grq4-qwgx