Uploaded image for project: 'Policy Framework'
  1. Policy Framework
  2. POLICY-4168

Security vulnerability when unzipping csar on distribution

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Medium Medium
    • Kohn Release
    • None
    • distribution
    • None

      Successful Zip Bomb attacks occur when an application expands untrusted archive files without controlling the size of the expanded data, which can lead to denial of service. A Zip bomb is usually a malicious archive file of a few kilobytes of compressed data but turned into gigabytes of uncompressed data. To achieve this extreme compression ratio, attackers will compress irrelevant data (eg: a long string of repeated bytes).

       

      https://sonarcloud.io/project/security_hotspots?id=onap_policy-distribution

            adheli.tavares Adheli Tavares
            adheli.tavares Adheli Tavares
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: