python / python/cpython

docs: Zipfile contains a 13-years outdated warning regarding path sanitization

Aberta Para iniciantes
#157,339 10 comentários 0 reações 0 responsáveis Ver no GitHub

Ninguém assumiu esta issue ainda.

docs pending
Linguagem predominante
Python
Estrelas
77.2k
Forks
36k
Métricas de merge de PRs
Métricas de PR pendentes

Descrição

Documentation

The extract/extractall documentation contains a warning that became outdated 13 years ago:

https://docs.python.org/3/library/zipfile.html#zipfile.ZipFile.extractall

"Warning: Never extract archives from untrusted sources without prior inspection. It is possible that files are created outside of path, for example, members that have absolute filenames or filenames with “..” components. This module attempts to prevent that. See extract() note."

This incorrect and completely outdated comment should have been deleted when the malicious zip sanitization was added to Python 13 years ago, in February 2013:

https://github.com/python/cpython/commit/b47acbf46abd425f69dcc03e9b4f0c7f7c321ac2

Here's the official Python code:

https://github.com/python/cpython/blob/main/Lib/zipfile/__init__.py#L2467

Both extract() and extractall() use _extract_member, which performs complete sanitizing:

# 1. Strips leading slashes (/), drive letters (C:), and UNC paths (\\server\share)
drive, root, arcname = os.path.splitroot(arcname)
...
# 2. Defines invalid parts: empty strings, current directory (.), and parent directory (..)
invalid_path_parts = ('', os.path.curdir, os.path.pardir)

# 3. Filters out any occurrences of '.' and '..'
arcname = os.path.sep.join(x for x in arcname.split(os.path.sep)
                           if x not in invalid_path_parts)

And even the original Zip Slip author said that Python is not vulnerable:

https://security.snyk.io/research/zip-slip-vulnerability

"We also vetted the Ruby and Python ecosystems and couldn’t find any vulnerable code snippets or libraries. In fact, Python libraries were vulnerable until fixed in 2014. Ruby has a number of existing vulnerabilities that have been fixed in previous versions here , here and here."

(He's wrong about 2014; Python added the malicious Zip path sanitization in February 2013.)

Guia de contribuição

Abrir o guia de contribuição

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Direção de pesquisa

Comece pela documentação de ZipFile.extractall vinculada na issue e revise a implementação relacionada de _extract_member em Lib/zipfile/init.py. Remova o aviso desatualizado sobre sanitização de caminhos e, em seguida, compile ou valide a documentação para confirmar que as referências a extract() e extractall() continuam corretas.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
python
Domínio
documentation
Tipo de issue
Documentação
Dificuldade
2/5
Tempo estimado
1-3 horas
Status de atividade
Ativa
Clareza
Claramente especificada
Facilidade para iniciantes
78/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.