login
quiescence.eu
Skip to content

CVE-2020-28949

PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability

n/a
CVSS
84.6%
EPSS (exploit prob.)
99.7%
EPSS percentile
Yes
Actively exploited
No
Ransomware use
2022-08-25
Added

Summary

PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.

Affected software

Vendor: PEAR  ·  Product: Archive_Tar

Weakness types (CWE):

CWE-74

What to do

This vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, meaning it is being exploited in the wild. Prioritize patching affected systems and verify exposure across your estate.

Related vulnerabilities in PEAR

CVENameEPSSExploited
CVE-2020-36193 PEAR Archive_Tar Improper Link Resolution Vulnerability 70.6% Yes

Is your domain exposed?

Run a free, instant security report for any domain — exposure score, email auth, TLS and breach metadata.

Get your free report

All information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.