{"id":"CVE-2020-36193","details":"Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.","aliases":["BIT-drupal-2020-36193","GHSA-rpw6-9xfx-jvcx"],"modified":"2026-07-08T05:59:29.624657356Z","published":"2021-01-18T20:15:12.667Z","related":["ALSA-2022:6542","SUSE-SU-2021:2926-1","SUSE-SU-2021:3006-1","SUSE-SU-2021:3018-1","openSUSE-SU-2021:1267-1","openSUSE-SU-2021:2872-1","openSUSE-SU-2021:3018-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"9.0"},{"last_affected":"9.0"},{"introduced":"10.0"},{"last_affected":"10.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux","cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"]},{"cpes":["cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"32"},{"last_affected":"32"},{"introduced":"33"},{"last_affected":"33"},{"introduced":"34"},{"last_affected":"34"},{"introduced":"35"},{"last_affected":"35"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora"}]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42GPGVVFTLJYAKRI75IVB5R45NYQGEUR/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FOZNK4FIIV7FSFCJNNFWMJZTTV7NFJV2/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VJQQYDAOWHD6RDITDRPHFW7WY6BS3V5N/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YKD5WEFA4WT6AVTMRAYBNXZNLWZHM7FH/"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-36193"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/01/msg00018.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/04/msg00007.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202101-23"},{"type":"ADVISORY","url":"https://www.debian.org/security/2021/dsa-4894"},{"type":"ADVISORY","url":"https://www.drupal.org/sa-core-2021-001"},{"type":"FIX","url":"https://github.com/pear/Archive_Tar/commit/cde460582ff389404b5b3ccb59374e9b389de916"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/drupal/drupal","events":[{"introduced":"497914920385b7016ac9c9367e0198530787adf2"},{"fixed":"8c555d9b7d3a202cee756104b48e580ae41a6379"},{"introduced":"a412ca41cfc0d954fe3cb2dd982dc6ca049b1c70"},{"fixed":"d890ca84f788f71f0066f1d06d93188f09bd3d6c"},{"introduced":"d62812dc17ce593beb2ccd4cdbee1a76c95e3fd7"},{"fixed":"e2c554ef842f5dc683d690f0a72a8f88569f8341"},{"introduced":"5c6f14f762c9aef87cd2731818386f202ee8463c"},{"fixed":"87ab5d42451bcc6850a46c2f87a80c69bee68fe1"}],"database_specific":{"extracted_events":[{"introduced":"7.0"},{"fixed":"7.78"},{"introduced":"8.9.0"},{"fixed":"8.9.13"},{"introduced":"9.0.0"},{"fixed":"9.0.11"},{"introduced":"9.1.0"},{"fixed":"9.1.3"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*"}}],"versions":["7.77","8.9.12","9.0.10","9.1.2","9.1.1","8.9.11","9.1.0","7.76","8.9.8","8.9.5","9.0.5","8.9.4","8.9.3","9.0.3","8.9.2","9.0.2","7.71","8.9.0","9.0.0","7.68","7.64","7.61","7.56","7.55","7.54","7.51","7.50","7.43","7.42","7.40","7.37","7.36","7.33","7.30","7.28","7.25","7.23","7.22","7.17","7.15","7.14","7.12","7.10","7.9","7.8","7.7","7.6","7.4","7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36193.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/pear/archive_tar","events":[{"introduced":"0"},{"last_affected":"17d355cb7d3c4ff08e5729f29cd7660145208d9d"},{"fixed":"cde460582ff389404b5b3ccb59374e9b389de916"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:php:archive_tar:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.4.11"}]}}],"versions":["1.4.11","1.4.10","1.4.9","1.4.8","1.4.7","1.4.6","1.4.5","1.4.4","1.4.2","1.4.3","1.4.1","1.4.0","1.3.13","1.3.12","1.3.11"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36193.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}