CVE-2020-36193 is a critical directory traversal vulnerability in Archive_Tar's Tar.php component, affecting products like Debian, Drupal, and PHP. This flaw allows unauthenticated attackers to perform arbitrary write operations due to insufficient symbolic link checks. With a CVSS score of 7.5 (HIGH) and an EPSS percentile of 99%, it poses a significant risk, enabling high integrity impact without requiring user interaction. Notably, this vulnerability is listed in CISA's KEV catalog, indicating active exploitation in the wild, despite no public Metasploit or ExploitDB modules. The vulnerability has garnered substantial community discussion and media coverage, highlighting its importance and the urgency for patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.4.11CPE matchmatch criteria | cpe:2.3:a:php:archive_tar:*:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.