« Back to list

PHP

PHP Archive TAR: vulnerabilities and CVEs

PHP Archive TAR has 4 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 2 are listed by CISA as actively exploited.

CVEs4
Last 12 months0
Critical0
Actively exploited2

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2020-28949High (7.8)85%⚠ Active exploitationNov 19, 2020
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
CVE-2020-36193High (7.5)71%⚠ Active exploitationJan 18, 2021
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2021-32610High (7.1)73%—Jul 30, 2021
In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
CVE-2020-36193High (7.5)71%⚠ Active exploitationJan 18, 2021
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
CVE-2020-28949High (7.8)85%⚠ Active exploitationNov 19, 2020
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
CVE-2020-28948High (7.8)47%—Nov 19, 2020
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1565.001 Stored Data Manipulation2
  2. T1190 Exploit Public-Facing Application1
  3. T1203 Exploitation for Client Execution1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by PHP