cashapp / misk

Microservice Kontainer
https://cashapp.github.io/misk/
Apache License 2.0
407 stars 170 forks source link

CCPOKR-14316 | [Security][High] - Arbitrary file access during archive extraction #3358

Closed katukota closed 4 months ago

katukota commented 4 months ago

Use the normalized path instead of the actual file name from JAR