CVE-2020-36193

CVE Published 2021-01-18
Related CWE(s) CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), CWE-59: Improper Link Resolution Before File Access ('Link Following')
Related Vendor(s) debian, drupal, php, fedoraproject
Related Product(s) fedora, debian_linux, drupal, archive_tar
Exploitation Reported (CISA KEV) 2022-08-25
CVSS 3 Base Score 7.5 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References