Loading
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
Use Php vendor hub and Archive Tar product page to widen CVE-2020-28949 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-36193, CVE-2020-28948 and CVE-2021-32610 for nearby disclosures in the same product family.