CVE-2020-24584: High severity django vulnerability
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-24584?
CVE-2020-24584 is a vulnerability discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1.
How severe is CVE-2020-24584?
CVE-2020-24584 has a severity rating of 7.5, which is considered high.
How does CVE-2020-24584 affect Django?
CVE-2020-24584 affects Django versions 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1.
What is the remedy for CVE-2020-24584?
The remedy for CVE-2020-24584 is to upgrade Django to version 3.1.1, 3.0.10, or 2.2.16 depending on the version you are using.
Where can I find more information about CVE-2020-24584?
You can find more information about CVE-2020-24584 in the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-24584), [GitHub](https://github.com/django/django/commit/1853724acaf17ed7414d54c7d2b5563a25025a71), [Django Releases](https://docs.djangoproject.com/en/dev/releases/security/)