Composer package intelligence

pear/archive_tar Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Composer package pear/archive_tar, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
2
Known exploited vulnerabilities affecting pear/archive_tar
In CISA KEV
2
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
pear/archive_tar KEVs with sensor-observed exploitation activity

Review pear/archive_tar exploitation against the versions you run

All two exploited pear/archive_tar vulnerabilities tracked here are also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested pear/archive_tar vulnerabilities

2 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2020-28949

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to...

In CISA 25 Aug 2022
CVE-2020-36193

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related...

In CISA 25 Aug 2022

Recurring weakness patterns

Improper Link Resolution Before File Access ('Link Following') account for mapped occurrences across this pear/archive_tar KEV portfolio.

Browse all KEVs →