snyk/zip-slip-vulnerability

java: link to updated Oracle documentation

Closed this issue · 2 comments

ecki commented

The entry for java.util.zip claims that Oracle has added documentation. Is this actually published already or is this only a expctation?

I asked on OpenJDK security-dev where that doc might be, but if Snyk members have the ansert from Oracle, can you provide the link?

http://mail.openjdk.java.net/pipermail/security-dev/2018-June/017404.html

hey @ecki we're checking to see if anyone in snyk got that link from Oracle. we'll let you (and the README) know

@ecki after checking internally, the problem is that there is no proper documentation. You can google for a couple of (vulnerable) entries on oracle blogs. We hope there will soon be clear docs in an accessible location.