mirror of
https://github.com/django/django.git
synced 2025-08-04 10:59:45 +00:00
Fixed CVE-2021-3281 -- Fixed potential directory-traversal via archive.extract().
Thanks Florian Apolloner, Shai Berger, and Simon Charette for reviews. Thanks Wang Baohua for the report.
This commit is contained in:
parent
6822aa5c6c
commit
05413afa8c
10 changed files with 77 additions and 5 deletions
BIN
tests/utils_tests/traversal_archives/traversal.tar
Normal file
BIN
tests/utils_tests/traversal_archives/traversal.tar
Normal file
Binary file not shown.
BIN
tests/utils_tests/traversal_archives/traversal_absolute.tar
Normal file
BIN
tests/utils_tests/traversal_archives/traversal_absolute.tar
Normal file
Binary file not shown.
BIN
tests/utils_tests/traversal_archives/traversal_disk_win.tar
Normal file
BIN
tests/utils_tests/traversal_archives/traversal_disk_win.tar
Normal file
Binary file not shown.
BIN
tests/utils_tests/traversal_archives/traversal_disk_win.zip
Normal file
BIN
tests/utils_tests/traversal_archives/traversal_disk_win.zip
Normal file
Binary file not shown.
Loading…
Add table
Add a link
Reference in a new issue