CVE-2020-28949
PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability
Summary
PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.
Affected software
Vendor: PEAR · Product: Archive_Tar
Weakness types (CWE):
What to do
This vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, meaning it is being exploited in the wild. Prioritize patching affected systems and verify exposure across your estate.
Related vulnerabilities in PEAR
| CVE | Name | EPSS | Exploited |
|---|---|---|---|
| CVE-2020-36193 | PEAR Archive_Tar Improper Link Resolution Vulnerability | 70.6% | Yes |
Is your domain exposed?
Run a free, instant security report for any domain — exposure score, email auth, TLS and breach metadata.
Get your free reportAll information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.