VDB
Sign up
—

DRUPAL-CORE-2020-013

Quick fix

DRUPAL-CORE-2020-013 — drupal/core: upgrade to the fixed version with the command below.

composer require drupal/core:^8.8.12

Details

The Drupal project uses the PEAR Archive\_Tar library. The PEAR Archive\_Tar library has released a security update that impacts Drupal. For more information please see:

* [CVE-2020-28948](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28948) * [CVE-2020-28949](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28949)

Multiple vulnerabilities are possible if Drupal is configured to allow `.tar`, `.tar.gz`, `.bz2`, or `.tlz` file uploads and processes them.

**To mitigate this issue, prevent untrusted users from uploading `.tar`, `.tar.gz`, `.bz2`, or `.tlz` files.**

This is a different issue than [SA-CORE-2019-012](https://www.drupal.org/sa-core-2019-012). Similar configuration changes may mitigate the problem until you are able to patch.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/drupal/core
Introduced in: 8.0.0Fixed in: 8.8.12
Fixcomposer require drupal/core:^8.8.12

References