Basically https://github.com/jenkinsci/jenkins/pull/3402 for untar in the same file.

          [JENKINS-51777] Fix "zip-slip" for tar archives

          Code changed in jenkins
          User: Daniel Beck
          Path:
          core/src/main/java/hudson/FilePath.java
          http://jenkins-ci.org/commit/jenkins/7438abb88fc7d9bbd5f2b265e8fb191179a3c553
          Log:
          JENKINS-51777 Don't let tar entries escape target dir

          SCM/JIRA link daemon added a comment - Code changed in jenkins User: Daniel Beck Path: core/src/main/java/hudson/FilePath.java http://jenkins-ci.org/commit/jenkins/7438abb88fc7d9bbd5f2b265e8fb191179a3c553 Log: JENKINS-51777 Don't let tar entries escape target dir

          Code changed in jenkins
          User: Oleg Nenashev
          Path:
          core/src/main/java/hudson/FilePath.java
          http://jenkins-ci.org/commit/jenkins/1afd9f8c6ea02d6e2e3b80eb384526b61f43cd80
          Log:
          Merge pull request #3482 from daniel-beck/zip-slip-tar

          JENKINS-51777 Don't let tar entries escape target dir

          Compare: https://github.com/jenkinsci/jenkins/compare/ee384ba34c4f...1afd9f8c6ea0
          *NOTE:* This service been marked for deprecation: https://developer.github.com/changes/2018-04-25-github-services-deprecation/

          Functionality will be removed from GitHub.com on January 31st, 2019.

          SCM/JIRA link daemon added a comment - Code changed in jenkins User: Oleg Nenashev Path: core/src/main/java/hudson/FilePath.java http://jenkins-ci.org/commit/jenkins/1afd9f8c6ea02d6e2e3b80eb384526b61f43cd80 Log: Merge pull request #3482 from daniel-beck/zip-slip-tar JENKINS-51777 Don't let tar entries escape target dir Compare: https://github.com/jenkinsci/jenkins/compare/ee384ba34c4f...1afd9f8c6ea0 * NOTE: * This service been marked for deprecation: https://developer.github.com/changes/2018-04-25-github-services-deprecation/ Functionality will be removed from GitHub.com on January 31st, 2019.

          Oleg Nenashev added a comment -

          Fixed in Jenkins 2.127

          Oleg Nenashev added a comment - Fixed in Jenkins 2.127

            danielbeck Daniel Beck
            danielbeck Daniel Beck
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: