CVE-2020-36566 is a critical vulnerability affecting tar_utils_project tar_utils, where improper path sanitization allows archives with relative file paths to write or overwrite files outside the intended directory. This vulnerability has a CVSS score of 9.1 (CRITICAL), indicating it can be exploited remotely with low complexity, leading to high impact on integrity and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with 10 mentions, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.0.0-20201201191210-20a61371de5bCPE matchmatch criteria | cpe:2.3:a:tar-utils_project:tar-utils:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.