logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2020-28949

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2020-28949

Description:
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
Last updated date:
06/28/2024

Reports

alt

ACTIVELY EXPLOITED

Type:
exploitation
Confidence:
HIGH
Date of publishing:
08/25/2022
Reference url to background

https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Type:
exploit
Confidence:
HIGH
Date of publishing:
06/26/2020
Type:
exploit
Confidence:
HIGH
Date of publishing:
02/02/2021
Type:
exploit
Confidence:
HIGH
Date of publishing:
02/02/2021
Type:
exploit
Confidence:
HIGH
Date of publishing:
08/27/2021
Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy