-
Notifications
You must be signed in to change notification settings - Fork 124
upgrade commons-io dependency version #1019
Copy link
Copy link
Open
Description
Hi, we found the insecure version of the dependency commons-io is still being used in the code:
Line 147 in 513d7a4
| dashPath = FilenameUtils.getPath( dashPath ); |
Test here:
@Test
public void testNormalize() throws Exception {
assertEquals(SEP + SEP + "127.0.0.1" + SEP + "a" + SEP + "b" + SEP + "c.txt", FilenameUtils.normalize("\\\\127.0.0.1\\a\\b\\c.txt"));
assertEquals(SEP + SEP + "::1" + SEP + "a" + SEP + "b" + SEP + "c.txt", FilenameUtils.normalize("\\\\::1\\a\\b\\c.txt"));
assertEquals(SEP + SEP + "1::" + SEP + "a" + SEP + "b" + SEP + "c.txt", FilenameUtils.normalize("\\\\1::\\a\\b\\c.txt"));
assertEquals(SEP + SEP + "server.example.org" + SEP + "a" + SEP + "b" + SEP + "c.txt", FilenameUtils.normalize("\\\\server.example.org\\a\\b\\c.txt"));
assertEquals(SEP + SEP + "server.sub.example.org" + SEP + "a" + SEP + "b" + SEP + "c.txt", FilenameUtils.normalize("\\\\server.sub.example.org\\a\\b\\c.txt"));
assertEquals(SEP + SEP + "server." + SEP + "a" + SEP + "b" + SEP + "c.txt", FilenameUtils.normalize("\\\\server.\\a\\b\\c.txt"));
assertEquals(SEP + SEP + "1::127.0.0.1" + SEP + "a" + SEP + "b" + SEP + "c.txt",
FilenameUtils.normalize("\\\\1::127.0.0.1\\a\\b\\c.txt"));
// not valid IPv4 addresses but technically a valid "reg-name"s according to RFC1034
assertEquals(SEP + SEP + "127.0.0.256" + SEP + "a" + SEP + "b" + SEP + "c.txt",
FilenameUtils.normalize("\\\\127.0.0.256\\a\\b\\c.txt"));
assertEquals(SEP + SEP + "127.0.0.01" + SEP + "a" + SEP + "b" + SEP + "c.txt",
FilenameUtils.normalize("\\\\127.0.0.01\\a\\b\\c.txt"));
assertEquals(null, FilenameUtils.normalize("\\\\-server\\a\\b\\c.txt"));
assertEquals(null, FilenameUtils.normalize("\\\\.\\a\\b\\c.txt"));
assertEquals(null, FilenameUtils.normalize("\\\\..\\a\\b\\c.txt"));
assertEquals(null, FilenameUtils.normalize("\\\\127.0..1\\a\\b\\c.txt"));
assertEquals(null, FilenameUtils.normalize("\\\\::1::2\\a\\b\\c.txt"));
assertEquals(null, FilenameUtils.normalize("\\\\:1\\a\\b\\c.txt"));
assertEquals(null, FilenameUtils.normalize("\\\\1:\\a\\b\\c.txt"));
assertEquals(null, FilenameUtils.normalize("\\\\1:2:3:4:5:6:7:8:9\\a\\b\\c.txt"));
assertEquals(null, FilenameUtils.normalize("\\\\g:2:3:4:5:6:7:8\\a\\b\\c.txt"));
assertEquals(null, FilenameUtils.normalize("\\\\1ffff:2:3:4:5:6:7:8\\a\\b\\c.txt"));
assertEquals(null, FilenameUtils.normalize("\\\\1:2\\a\\b\\c.txt"));
}
@Test
public void testNormalizeUnixWin() throws Exception {
assertEquals(12, FilenameUtils.getPrefixLength("\\\\127.0.0.1\\a\\b\\c.txt"));
assertEquals(6, FilenameUtils.getPrefixLength("\\\\::1\\a\\b\\c.txt"));
assertEquals(21, FilenameUtils.getPrefixLength("\\\\server.example.org\\a\\b\\c.txt"));
assertEquals(10, FilenameUtils.getPrefixLength("\\\\server.\\a\\b\\c.txt"));
assertEquals(-1, FilenameUtils.getPrefixLength("\\\\-server\\a\\b\\c.txt"));
assertEquals(-1, FilenameUtils.getPrefixLength("\\\\.\\a\\b\\c.txt"));
assertEquals(-1, FilenameUtils.getPrefixLength("\\\\..\\a\\b\\c.txt"));
}
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels