crate / crate/crate-python

[Security] tarfile.extractall without member validation in src/crate/testing/layer.py

Đang mở
#794 2 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
Python
Star
85
Fork
34
Merge trung bình
3 ngày 16 giờ
Pull request đã merge (30 ngày)
3

Mô tả

**Severity**: HIGH (Bandit B202)
**File**: `src/crate/testing/layer.py`

## Vulnerability

`tarfile.extractall()` without member validation allows path traversal (zip slip). A malicious archive can write files outside the target directory.

## Fix

```python
import os

SAFE_ID = __import__("re").compile(r"^[a-zA-Z0-9_.-]+$")

def _is_within_directory(directory, target):
abs_directory = os.path.realpath(directory)
abs_target = os.path.realpath(target)
return abs_target.startswith(abs_directory + os.sep) or abs_target == abs_directory

def safe_extract(tar, path=".", members=None, *, numeric_owner=False):
for member in tar.getmembers():
member_path = os.path.join(path, member.name)
if not _is_within_directory(path, member_path):
raise Exception(f"Path traversal in tar: {member.name}")
tar.extractall(path, members, numeric_owner=numeric_owner)
```

## References
- CWE-22: Path Traversal
- Bandit B202
- [OWASP: Zip Slip](https://owasp.org/www-community/attacks/Zip_Slip)

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.