FlawAtlas
Search the atlas
CVE-2021-32610 High

CVE-2021-32610

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

Exploit probability 73.4%
Published July 30, 2021
Required by Not available
Last source change July 8, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

18 explicit affected versions

Packagist pear/archive_tar

20 explicit affected versions

Packagist drupal/core

174 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2021-32610

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

View original source
Open Source Vulnerabilities DRUPAL-CORE-2021-004

The Drupal project uses the pear Archive\_Tar library, which has released a security update that impacts Drupal. The vulnerability is mitigated by the fact that Drupal core's use of the Archive\_Tar library is not vulnerable, as it does not permit symlinks. Exploitation may be possible if contrib or custom code uses the library to extract tar archives (for example .tar, .tar.gz, .bz2, or .tlz) which come from a potentially untrusted source. This advisory is not covered by [Drupal Steward](/steward).

View original source
Open Source Vulnerabilities GHSA-p8q8-jfcv-g2h2

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

View original source

05 / REFERENCES

Further evidence