Uploaded image for project: 'Policy Framework'
  1. Policy Framework
  2. POLICY-4168

Security vulnerability when unzipping csar on distribution

    XMLWordPrintable

Details

    • Story
    • Status: Closed
    • Medium
    • Resolution: Done
    • None
    • Kohn Release
    • distribution
    • None

    Description

      Successful Zip Bomb attacks occur when an application expands untrusted archive files without controlling the size of the expanded data, which can lead to denial of service. A Zip bomb is usually a malicious archive file of a few kilobytes of compressed data but turned into gigabytes of uncompressed data. To achieve this extreme compression ratio, attackers will compress irrelevant data (eg: a long string of repeated bytes).

       

      https://sonarcloud.io/project/security_hotspots?id=onap_policy-distribution

      Attachments

        No reviews matched the request. Check your Options in the drop-down menu of this sections header.

        Activity

          People

            adheli.tavares Adheli Tavares
            adheli.tavares Adheli Tavares
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: