tbitonti / jakartaee-prototype

Other
0 stars 9 forks source link

Handle ZipSlip vulnerability when processing ZipEntry names in a zip file #60

Open bjhargrave opened 4 years ago

bjhargrave commented 4 years ago

See https://github.com/bndtools/bnd/blob/ea6b9b1d3e097a443d707a6623d8542044bf4c94/aQute.libg/src/aQute/lib/zip/ZipUtil.java#L29-L76 for a method to clean a zip entry name which fails upon a malformed zip entry name.