italia / spid-saml-check

Tool di verifica implementazione SPID SAML
European Union Public License 1.2
71 stars 59 forks source link

Possible vulnerability in ZIP decompression #260

Open bfabio opened 8 months ago

bfabio commented 8 months ago

https://github.com/italia/spid-saml-check/blob/414e2b72d7506f19fe0a956847a5e405becf9f34/spid-validator/server/api/metadata-sp.js#L219 unzips the file passed in by the user, I think a simple zip bomb would DoS the entire server.

Also unzip latest release was 9 years ago and looks unmaintained.