zip-lib is vulnerable to Zip Slip
75
High Risk
Affected versions of this package are vulnerable to a directory traversal or zip slip issue during ZIP extraction. When extracting multiple ZIP files, an attacker can bypass the isOutsideTargetFolder check by first extracting a ZIP file containing a symlink to an arbitrary directory (e.g., /tmp/) and then extracting another ZIP file with files or symlinks targeting that location. This allows files to be written outside the intended extraction directory, potentially leading to unauthorized file writes.
You are affected if you are use a vulnerable version of torchserve.
zip-lib is vulnerable to Zip Slip in versions 0.1.0 - 1.0.5.
Upgrade zip-lib to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant