microsoft / vsminecraft

Visual Studio extension for developing MinecraftForge mods using Java.
Other
194 stars 25 forks source link

zip_slip #42

Open QiAnXinCodeSafe opened 5 years ago

QiAnXinCodeSafe commented 5 years ago

The Entry name is not verified when extracting the zip file in the deployEntry method in the ThreadClientUpdate.java file. As a result, when extracting a maliciously constructed zip file("../" in entry name) from an attacker, it may overwrite sensitive files in the system. 图片