]> git.immae.eu Git - github/fretlink/terraform-provider-statuscake.git/blobdiff - vendor/github.com/hashicorp/go-getter/decompress_zip.go
deps: github.com/hashicorp/terraform@sdk-v0.11-with-go-modules
[github/fretlink/terraform-provider-statuscake.git] / vendor / github.com / hashicorp / go-getter / decompress_zip.go
index a065c076ffe3a1f1d56b0418b794ddd4977ad664..b0e70cac35c432aec38bf5a00f0b9a900280a081 100644 (file)
@@ -42,6 +42,11 @@ func (d *ZipDecompressor) Decompress(dst, src string, dir bool) error {
        for _, f := range zipR.File {
                path := dst
                if dir {
+                       // Disallow parent traversal
+                       if containsDotDot(f.Name) {
+                               return fmt.Errorf("entry contains '..': %s", f.Name)
+                       }
+
                        path = filepath.Join(path, f.Name)
                }