There are known exploits! Drupal core - Critical - Arbitrary PHP code execution - SA-CORE-2020-013
Project: Drupal core
Date: 2020-November-25
Security risk: Critical 18∕25
Vulnerability: Arbitrary PHP code execution
CVE IDs: CVE-2020-28949,CVE-2020-28948
Description
The Drupal project uses the PEAR Archive_Tar library. The PEAR Archive_Tar library has released a security update that impacts Drupal. For more information please see: