CVE-2020-36193

CVE Published 2021-01-18
Related CWE(s) CWE-59: Improper Link Resolution Before File Access ('Link Following'), CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Related Vendor(s) fedoraproject, drupal, debian, php
Related Product(s) fedora, drupal, archive_tar, debian_linux
Exploitation Reported (CISA KEV) 2022-08-25
CVSS 3 Base Score 7.5 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References