Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rpw6-9xfx-jvcx

Опубликовано: 22 апр. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Directory Traversal in Archive_Tar

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

:exclamation: Note:

There was an initial fix for this vulnerability made in version 1.4.12. That fix introduced a bug which was fixed in 1.4.13. Therefore we have set the first-patched-version to 1.4.13 which the earliest working version that avoids this vulnerability.

Пакеты

Наименование

pear/archive_tar

composer
Затронутые версииВерсия исправления

<= 1.4.11

1.4.13

EPSS

Процентиль: 99%
0.81263
Высокий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

CVSS3: 7.5
redhat
больше 4 лет назад

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

CVSS3: 7.5
nvd
больше 4 лет назад

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

CVSS3: 7.5
debian
больше 4 лет назад

Tar.php in Archive_Tar through 1.4.11 allows write operations with Dir ...

suse-cvrf
почти 4 года назад

Security update for php7-pear

EPSS

Процентиль: 99%
0.81263
Высокий

7.5 High

CVSS3

Дефекты

CWE-22