Skip to content

DotNetZip Directory Traversal security vulnerability #6

@ShaunKrog

Description

@ShaunKrog

Describe the issue
As per advisory, https://github.com/advisories/GHSA-xhg6-9j5j-w4vfm, high severity vulnerability. Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry.Extract.cs component.

Describe the improvement you'd like
Upgrade to newest version of Dotnet Zip compliant with Dotnet 6.0

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions