-
-
Notifications
You must be signed in to change notification settings - Fork 265
Closed
Description
Possible Security Issue
Configuration
Keka version: Version 1.1.30 (3477)
macOS version: macOS 10.14.6 (18G6020)
Describe the bug
Create a zip with a password and 256 encryption. I upload these to Google Drive (web interface) and without password I can see the content of one of the zips, in Google Drive. I repeated with that folder, same result. This is quite a security issue if I don't miss a step.
To Reproduce
Steps to reproduce the behavior:
- set Keka with ZIP 256bits encryption
- Drop several folders to zip them individually, then upload these to Google Drive.
- Then I noticed I didn't setup encryption on first one, so deleted it from Google Drive, re zipped it localy with encryption and uploaded again. I could see content in Google Drive!
- I then tried again changing the name of the folder before zipping it, thinking to avoid potential issues with that (upload delete reupload same name file). But same again, content accessible.Wow