CVE-2022-23596 is a high-severity vulnerability affecting the Junrar Java RAR archive library, where a specially crafted RAR archive can cause an infinite loop during extraction. This denial-of-service vulnerability has a CVSS score of 7.5, indicating it can be exploited remotely without user interaction to cause high availability impact. While there are no known exploits or active exploitation, the vulnerability has received some community discussion, and users are strongly advised to upgrade to version 7.4.1 or later as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.4.1CPE matchmatch criteria | cpe:2.3:a:junrar_project:junrar:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.