Drupal released security updates to fix the vulnerabilities resided in the Drupal Core and the PEAR Archive_tar library. An authenticated user may execute arbitrary code from local PHP files or PHAR archives in a vulnerable system.
Please note that versions of Drupal 8 prior to 8.5.x are also vulnerable. However, the support for such versions are ceased and no security updates will be provided. Users should upgrade the Drupal to a supported branch or arrange migrating to other supported technology.
A successful attack could lead to remote code execution on an affected system.
The product vendor has released patches to address the issues.
https://www.drupal.org/sa-core-2019-001
https://www.drupal.org/sa-core-2019-002
https://www.hkcert.org/my_url/en/alert/19011701
https://www.us-cert.gov/ncas/current-activity/2019/01/16/Drupal-Releases-Security-Updates
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000888