[ https://issues.apache.org/jira/browse/FLINK-29122?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17585389#comment-17585389 ]
Robert Metzger commented on FLINK-29122: ---------------------------------------- Draft: https://github.com/rmetzger/flink/pull/new/expand_dir CI: https://dev.azure.com/rmetzger/Flink/_build/results?buildId=9224&view=results > Improve robustness of FileUtils.expandDirectory() > -------------------------------------------------- > > Key: FLINK-29122 > URL: https://issues.apache.org/jira/browse/FLINK-29122 > Project: Flink > Issue Type: Bug > Components: API / Core > Affects Versions: 1.16.0, 1.17.0 > Reporter: Robert Metzger > Assignee: Robert Metzger > Priority: Major > > `FileUtils.expandDirectory()` can potentially write to invalid locations if > the zip file is invalid (contains entry names with ../). -- This message was sent by Atlassian Jira (v8.20.10#820010)