CVE-2020-28949

CVE Published 2020-11-19
Related CWE(s) CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Related Vendor(s) fedoraproject, drupal, debian, php
Related Product(s) fedora, drupal, archive_tar, debian_linux
Exploitation Reported (CISA KEV) 2022-08-25
CVSS 3 Base Score 7.8 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector LOCAL

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References