← back
CVE-2020-28949highunder attack

CVE-2020-28949

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 7.8epss 85%
from disclosure to weapon683 days
Published on NVDNov 19
1st PoC+683d
metasploitNov 17
CISA KEV+644d
exploitation probability
85%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
Action required by CISAfederal deadline: 2022-09-15

Apply updates per vendor instructions.

Versions

Affected
composer/pear/archive_tar < 1.4.11
Fixed in
composer/pear/archive_tar 1.4.11
Researched and written with AI from the vendor advisory and public analysis, with the sources above. Always confirm the fixed version in the official advisory before acting.
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.