CVE-2020-28949
Known Exploited (CISA KEV)HIGH
7.8
CVSS Severity Score
Vulnerability Description
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
Affected Platforms (CPE)
π¦
Php
Archive Tar
< 1.4.12π»
Debian
Debian Linux
= 9.0π»
Debian
Debian Linux
= 10.0π»
Fedoraproject
Fedora
= 32π»
Fedoraproject
Fedora
= 33π»
Fedoraproject
Fedora
= 34π»
Fedoraproject
Fedora
= 35π¦
Drupal
Drupal
>= 7.0 and < 7.75π¦
Drupal
Drupal
>= 8.0.0 and < 8.9.10π¦
Drupal
Drupal
>= 8.8.0 and < 8.8.12π¦
Drupal
