[GitHub] [geronimo-batchee] JLLeitschuh opened a new pull request, #12: [SECURITY] Fix Zip Slip Vulnerability

2022-11-04 Thread GitBox
JLLeitschuh opened a new pull request, #12: URL: https://github.com/apache/geronimo-batchee/pull/12 # Security Vulnerability Fix This pull request fixes a Zip Slip vulnerability either due to an insufficient, or missing guard when unzipping zip files. Even if you deem, as

[GitHub] [geronimo-batchee] JLLeitschuh commented on pull request #12: [SECURITY] Fix Zip Slip Vulnerability

2022-11-04 Thread GitBox
JLLeitschuh commented on PR #12: URL: https://github.com/apache/geronimo-batchee/pull/12#issuecomment-1303818287 Hi @rmannibucau, This pull request, along with 164 similar pull request, was automatically generated at-scale to fix this vulnerability across the OSS java ecosystem.

[GitHub] [geronimo-batchee] rmannibucau commented on pull request #12: [SECURITY] Fix Zip Slip Vulnerability

2022-11-04 Thread GitBox
rmannibucau commented on PR #12: URL: https://github.com/apache/geronimo-batchee/pull/12#issuecomment-1303811303 Hi, agree that even if it is not exploitable by most env it is good to get it merged. Can you work on a test validating the PR fixes the issue before we integrate it please?