Skip to content

Mitigating ZipSlip vulnerability #6630

Merged
agibsonccc merged 2 commits intodeeplearning4j:masterfrom
conikeec:master
Oct 24, 2018
Merged

Mitigating ZipSlip vulnerability #6630
agibsonccc merged 2 commits intodeeplearning4j:masterfrom
conikeec:master

Conversation

@conikeec
Copy link
Copy Markdown

patched org/nd4j/util/ArchiveUtils.java to mitigate ZipSlip vulnerability (https://nakedsecurity.sophos.com/2018/06/06/the-zip-slip-vulnerability-what-you-need-to-know/)

Copy link
Copy Markdown
Contributor

@agibsonccc agibsonccc left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor nitpick on logging.

@conikeec
Copy link
Copy Markdown
Author

conikeec commented Oct 24, 2018

Changes applied (log nitpick suggestion)

@agibsonccc
Copy link
Copy Markdown
Contributor

If that's how you want to do it. I thought you wanted to add the target dir as a log message. Thanks for the fix!

@agibsonccc agibsonccc merged commit f51f424 into deeplearning4j:master Oct 24, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants