-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from Drupal's use of unpatched PEAR Archive_Tar library versions in its archive handling components. Both Drupal 7's archiver.inc and Drupal 8+/9's Tar.php implement archive extraction via Archive_Tar::extract(). The CVEs specifically relate to Archive_Tar's failure to sanitize filenames during extraction, allowing attackers to write arbitrary files (including PHP files) via crafted archives. Drupal's wrapper functions become vulnerable entry points because they directly interface with the insecure library without additional sanitization in affected versions.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| drupal/core | composer | >= 7.0.0, < 7.75 | 7.75 |
| drupal/core | composer | >= 8.0.0, < 8.8.12 | 8.8.12 |
| drupal/core | composer |
| >= 8.9.0, < 8.9.10 |
| 8.9.10 |
| drupal/core | composer | >= 9.0.0, < 9.0.9 | 9.0.9 |
Ongoing coverage of React2Shell