← All CVEs

CVE-2020-36193

high · 7.5Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-08-25Remediation due 2022-09-15

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

7.5
CVSS
70.6%
EPSS (exploit prob.)
99th
EPSS percentile
2021-01-18
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Weaknesses

CWE-22CWE-59

Affected products

VendorProductAffected versions
phparchive_tar<= 1.4.11
fedoraprojectfedora32
fedoraprojectfedora33
fedoraprojectfedora34
fedoraprojectfedora35
debiandebian_linux9.0
debiandebian_linux10.0
drupaldrupal>= 7.0, < 7.78
drupaldrupal>= 8.9.0, < 8.9.13
drupaldrupal>= 9.0.0, < 9.0.11
drupaldrupal>= 9.1.0, < 9.1.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-36193