snyk/zip-slip-vulnerability

zip4j 1.3.3 does not exist

Closed this issue · 1 comments

j4rv commented

The README says that the zip4j library fixes this vulnerability in its version '1.3.3'.

But this version is not available in the maven repository (https://mvnrepository.com/artifact/net.lingala.zip4j/zip4j) and the linked jar in the developer's page is almost empty (783 bytes) (http://www.lingala.net/zip4j/download.php)

Version 1.3.3 with Zip slip fix is now available in maven repository