CVE-2020-7063


Files added to tar with Phar::buildFromIterator have all-access permissions

In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR archive using PharData::buildFromIterator() function, the files are added with default permissions (0666, or all access) even if the original files on the filesystem were with more restrictive permissions. This may result in files having more lax permissions than intended when such archive is extracted.



We have discovered 597,107 live websites that are affected by CVE-2020-7063.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 7.2 before 7.2.28
  • from 7.3 before 7.3.15
  • from 7.4 before 7.4.3
Total Vulnerable Versions507
Vulnerable Domains597,107 live websites (4.94% of PHP install base)


Common Weakness Enumeration


CWE-281 Improper Preservation of Permissions


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2020-7063 and the relative popularity of websites


Details

  • Published - Feb 17, 2020
  • Updated - Jul 23, 2021

Credits

  • Reported by dr at loopia dot rs





Countries

United States116,767 websites



France243,435 websites
Russia65,483 websites
China19,774 websites
Poland12,637 websites
Germany12,579 websites
Italy11,587 websites
Belgium11,540 websites
Spain9,542 websites
GB9,259 websites

TLDs

.com243,650 websites
.fr108,916 websites
.ru63,371 websites
.org23,678 websites
.net15,905 websites
.be12,936 websites
.pl9,936 websites
.it8,714 websites
.de7,647 websites
.nl6,669 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2020-7063 through included software libraries and plugins.



References


Websites affected by CVE-2020-7063

Top websites that are affected by CVE-2020-7063. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*****.cz Czech Republic*,***
*.cn China*,***
***.*.cn China*,***
*****.***.cn China*,***
***.*****.***.cn China*,***
*****.cn China*,***
***.*****.cn China*,***
***.*********.com China*,***
*.***.cn China*,***
***.*.***.cn China*,***
See full domain list