← Back to browse · API

CVE-2020-28949

Severity
HIGH
CVSS
7.8
EPSS
0.84554
Risk score
85.79
CISA KEV
Yes
PoC
No
Published
2022-08-25
Modified
2022-08-25
First seen
2026-08-07
Aliases
EUVD-2021-0783, GHSA-75C5-F4GW-38R9
Products
PEAR:Archive_Tar, n/a:n/a n/a
Sources
euvd EUVD-2021-0783
cisa.gov CVE-2020-28949

Description

PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.

References