MEDIUM 5.5 Maven
Junrar vulnerable to Infinite Loop
GHSA-5xqr-grq4-qwgx · CVE-2018-12418
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulnerability due to an infinite loop when handling corrupt RAR files.
Ready to move
Start Securing
Free, no credit card | First findings in minutes