PT-2020-5498 · Django Software Foundation+4 · Django+4
Published
2020-09-01
·
Updated
2026-01-03
·
CVE-2020-24584
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Django versions 2.2 through 2.2.15
Django versions 3.0 through 3.0.9
Django versions 3.1 through 3.1.0
Description
The issue is related to incorrect default permission settings in the Django web application platform. This could allow a remote attacker to disclose protected information. The problem arises from the intermediate-level directories of the filesystem cache having the system's standard umask rather than 0o077.
Recommendations
For Django versions 2.2 through 2.2.15, update to version 2.2.16 or later.
For Django versions 3.0 through 3.0.9, update to version 3.0.10 or later.
For Django versions 3.1 through 3.1.0, update to version 3.1.1 or later.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Django
Linuxmint
Ubuntu