Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-24584

Опубликовано: 01 сент. 2020
Источник: debian

Описание

An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-djangofixed2:2.2.16-1package
python-djangonot-affectedstretchpackage

Примечания

  • https://github.com/django/django/commit/1853724acaf17ed7414d54c7d2b5563a25025a71 (master)

  • https://github.com/django/django/commit/2b099caa5923afa8cfb5f1e8c0d56b6e0e81915b (3.1.1)

  • https://github.com/django/django/commit/cdb367c92a0ba72ddc0cbd13ff42b0e6df709554 (3.0.10)

  • https://github.com/django/django/commit/a3aebfdc8153dc230686b6d2454ccd32ed4c9e6f (2.2.16)

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.

CVSS3: 7.5
redhat
почти 5 лет назад

An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.

CVSS3: 7.5
nvd
почти 5 лет назад

An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.

CVSS3: 7.5
github
больше 4 лет назад

Django Incorrect Default Permissions

CVSS3: 7.5
fstec
почти 5 лет назад

Уязвимость программной платформы для веб-приложений Django, связанная с связана с неправильными настройками прав доступа по умолчанию, позволяющая нарушителю раскрыть защищаемую информацию