The developers of the Drupal content management system (CMS) have released emergency security due to the availability of some exploitsthat can compromise systems.

The core updates released for Drupal 7, 8.8, 8.9, and 9.0 on November 25 address two vulnerabilities affecting PEAR Archive_Tar, a third-party library designed for handling files in PHP.
The updates fix two vulnerabilities that have been named CVE-2020-28948 and CVE-2020-28949.
The exploit involves handling file names and can allow an attacker to execute PHP code or replace files, including critical files such as /etc/passwd and /etc/shadow.
The researcher who reported the vulnerabilitiesalso published proof-of-concept (PoC) exploits, which is why Drupal developers decided to release emergency updates for users to protect them from a potential attack.
According to the update schedule, the patch released on November 25th is not a major update. However, it was necessary because there are known exploits that make certain Drupal configurations vulnerable to attacks.

Drupal developers pointed out that the exploit is possible if the CMS is configured to allow uploading of .tar, .tar.gz, .bz2 or .tlz files. Last year, similar vulnerabilities related to the same PEAR library were fixed. The developers said that the current vulnerabilities are not related to last year's, although the same configuration changes can mitigate the issue. One of the tips that experts give to users is to prohibit untrusted users from uploading files with the aforementioned extensions.
This is the sixth security released this year for the Drupal CMS. The fifth patch was also released this month to fix a vulnerability that could allow an attacker to execute code remotely.
Source: Security Week
