Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-24654

17
FAUCET Score

CVE-2020-24654 describes a path traversal vulnerability in KDE Ark versions prior to 20.08.1, allowing a crafted TAR archive with symbolic links to write files outside the intended extraction directory. This low-severity vulnerability (CVSS 3.3) requires user interaction and local access, with a potential impact of unauthorized file modification. There is no evidence of active exploitation, public exploit code, or significant community discussion, indicating a low immediate threat level.

Impacted Technologies

VendorProductVersion(s)CPE
< 20.08.1CPE matchmatch criteria
cpe:2.3:a:kde:ark:*:*:*:*:*:*:*:*
16.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
18.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
20.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.3LOW

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.50%
Probability of exploitation in next 30 days
EPSS Percentile
71.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0150 is in the 77th percentile among its peer group of 577 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: ark

Vendor Advisories (1)

redhatCVE-2020-24654Low

ark: crafted TAR archive with symlinks can install files outside the extraction directory

Aug 27, 2020

References

lists.opensuse.org / opensuse-security-announce/2020-09/msg00001.html
Mailing ListThird Party Advisory
bugzilla.suse.com / show_bug.cgi
Issue TrackingThird Party Advisory
github.com / KDE/ark/commit/8bf8c5ef07b0ac5e914d752681e470dea403a5bd
PatchThird Party Advisory
kde.org / info/security/advisory-20200827-1.txt
Vendor Advisory
lists.debian.org / debian-lts-announce/2022/05/msg00026.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/LXMMXNJDYOCJRZTESIUGHG6CS4RJKECX
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/YJOZ6YRNPZX5MJGVBMOCOA7N6Z4EU2OK
security.gentoo.org / glsa/202010-06
Third Party Advisory
security.gentoo.org / glsa/202101-06
Third Party Advisory
usn.ubuntu.com / 4482-1
Third Party Advisory
debian.org / security/2020/dsa-4759
Third Party Advisory