Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit cc47b90

Browse files
Introduced protections against "zip slip" attacks (#3)
Co-authored-by: pixeebot[bot] <104101892+pixeebot[bot]@users.noreply.github.com>
1 parent f463538 commit cc47b90

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

interlok-core/src/main/java/com/adaptris/core/lms/ZipFileBackedMessageImpl.java

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,7 @@
1616

1717
package com.adaptris.core.lms;
1818

19+
import io.github.pixee.security.ZipSecurity;
1920
import java.io.File;
2021
import java.io.IOException;
2122
import java.io.InputStream;
@@ -70,7 +71,7 @@ private InputStream openInputStream() throws IOException {
7071
}
7172
}
7273
if (isZip) {
73-
ZipInputStream zin = new ZipInputStream(super.getInputStream());
74+
ZipInputStream zin = ZipSecurity.createHardenedInputStream(super.getInputStream());
7475
zin.getNextEntry();
7576
return zin;
7677
}

0 commit comments

Comments
 (0)