Uploaded image for project: 'ZK'
  1. ZK
  2. ZK-748

Pathn transversal detected by Veracode in class org.zkoss.zk.ui.http.AbstractExtendlet

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Normal Normal
    • 5.0.11
    • 5.0.7
    • None
    • None

      Hi,

      We are currently using zk 5.0.7 and during veracode analysis on our deploy, this scanner found out that there is an unsafe usage of path at line 218 in class org.zkoss.zk.ui.http.AbstractExtendlet.

      return new File(_parent, path).toURI().toURL();

      We would appreciate your collaboration with this issue.
      Thanks in advance.

            Jenkins Jenkins
            alejo0920 alejo0920
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 30 minutes
                30m