---
title: "Drupal Archive_Tar Vulnerability &#8211; 12/18/2019"
description: "Issue:On December 18, 2019, Archive_Tar, used in the Drupal content management system (CMS), has many vulnerabilities if a Drupal website is set to allow and process .tar, .tar.gz, .bz2, or .tlz file..."
url: https://www.inmotionhosting.com/support/edu/drupal/drupal-archive-tar-vulnerability/
date: 2019-12-23
modified: 2022-11-30
author: "InMotion Hosting Contributor"
categories: ["Drupal"]
type: post
lang: en
---

# Drupal Archive_Tar Vulnerability &#8211; 12/18/2019

| **Issue:** | On December 18, 2019, Archive_Tar, used in the Drupal content management system (CMS), has many vulnerabilities if a Drupal website is set to allow and process .tar, .tar.gz, .bz2, or .tlz file uploads |
| --- | --- |
| **Versions affected ?** | 8.8.x-dev 8.7.x-dev 7.x-dev |
| **Recommendation:** | [Update Drupal 8](https://www.inmotionhosting.com/support/edu/drupal/update-drupal-8-manually/) [Update Drupal 7](https://www.inmotionhosting.com/support/edu/drupal/306-manual-update/) |
| **Source:** | [https://www.drupal.org/sa-core-2019-012](https://www.drupal.org/sa-core-2019-012) |

Check out our [Drupal 8 Education channel](https://www.inmotionhosting.com/support/edu/drupal/drupal-8-release/) for many helpful tutorials, and learn more about server security in our with our guide on [Top Ways to Harden VPS Hosting](https://www.inmotionhosting.com/support/product-guides/vps-hosting/ways-to-harden-your-vps-hosting/).
