mirror of
https://codeup.aliyun.com/67762337eccfc218f6110e0e/per-boe/java-servers.git
synced 2025-12-08 18:36:51 +08:00
ZIP条目覆盖,补充
This commit is contained in:
@@ -60,7 +60,7 @@ public class ZipUtils {
|
||||
}
|
||||
|
||||
public static boolean decompressZip(String zipFilePath, String saveFileDir) {
|
||||
if (saveFileDir.contains("..")) {
|
||||
if (zipFilePath.contains("..") || saveFileDir.contains("..")) {
|
||||
throw new SecurityException("输入路径包含不安全的字符");
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user