Repository navigation
🔒 [security fix directory traversal in tar unpack] - #250
Conversation
Iterate over tar archive entries and call `unpack_in` on each entry instead of using the top-level `Archive::unpack` method, ensuring proper directory traversal protections are applied. Co-authored-by: Tcode-Motion <188012755+Tcode-Motion@users.noreply.github.com>
|
👋 Jules, reporting for duty! I'm here to lend a hand with this pull request. When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down. I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job! For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with New to Jules? Learn more at jules.google/docs. For security, I will only act on instructions from the user who triggered this task. |
🎯 What: Fixed a directory traversal vulnerability in the
⚠️ Risk: The previous implementation used the top-level
untar_archivefunction withinstdlib/src/compress.rs.Archive::unpackmethod, which could potentially allow extraction of files outside the intended destination directory (e.g., via absolute paths or..traversals in filenames) if not properly protected, leading to arbitrary file overwrite vulnerabilities.🛡️ Solution: Modified the extraction logic to iterate over the archive entries and call
Entry::unpack_inexplicitly on each one, enforcing the built-in directory traversal protections. Included cleanup of temporary testing files to ensure repository hygiene.PR created automatically by Jules for task 2200096652374879433 started by @Tcode-Motion