CVE-2020-28948: Debian Linux
High severity, CVSS 7.8. EPSS: 47.5% chance of exploitation in the next 30 days.
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
Affected products
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Drupal Drupal: from 7.0, before 7.75 (fixed in 7.75); from 8.0.0, before 8.9.10 (fixed in 8.9.10); from 8.8.0, before 8.8.12 (fixed in 8.8.12); from 9.0.0, before 9.0.9 (fixed in 9.0.9)
- Fedoraproject Fedora: version 32 only; version 33 only; version 34 only; version 35 only
- PHP Archive Tar: before 1.4.11 (fixed in 1.4.11)
Published 2020-11-19. Last modified 2026-06-17.