PT-2020-5498 · Django Software Foundation+4 · Django+4

Published

2020-09-01

·

Updated

2026-01-03

·

CVE-2020-24584

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Django versions 2.2 through 2.2.15 Django versions 3.0 through 3.0.9 Django versions 3.1 through 3.1.0
Description The issue is related to incorrect default permission settings in the Django web application platform. This could allow a remote attacker to disclose protected information. The problem arises from the intermediate-level directories of the filesystem cache having the system's standard umask rather than 0o077.
Recommendations For Django versions 2.2 through 2.2.15, update to version 2.2.16 or later. For Django versions 3.0 through 3.0.9, update to version 3.0.10 or later. For Django versions 3.1 through 3.1.0, update to version 3.1.1 or later.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3491
BDU:2021-00881
BIT-DJANGO-2020-24584
CVE-2020-24584
DLA-3164-1
GHSA-FR28-569J-53C4
OPENSUSE-SU-2024:11205-1
OPENSUSE-SU-2024:13887-1
OPENSUSE-SU-2024:14208-1
OPENSUSE-SU-2026:10005-1
PYSEC-2020-34
USN-4479-1

Affected Products

Alt Linux
Astra Linux
Django
Linuxmint
Ubuntu