CVE-2020-28948 is an unserialization vulnerability in Archive_Tar versions through 1.4.10, affecting products like Debian, Drupal, and PHP, due to insufficient blocking of the "PHAR:" protocol. This high-severity vulnerability (CVSS 7.8) has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability if a user is tricked into interacting with a malicious archive. While not listed in KEV, it has known exploits, as evidenced by Drupal's emergency patches and extensive media coverage, indicating significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.11CPE matchmatch criteria | cpe:2.3:a:php:archive_tar:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.