High severity7.5NVD Advisory· Published Sep 1, 2020· Updated Jun 17, 2026
CVE-2020-24583
CVE-2020-24583
Description
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level directories created in the process of uploading files. It was also not applied to intermediate-level collected static directories when using the collectstatic management command.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
DjangoPyPI | >= 2.2a1, < 2.2.16 | 2.2.16 |
DjangoPyPI | >= 3.0a1, < 3.0.10 | 3.0.10 |
DjangoPyPI | >= 3.1a1, < 3.1.1 | 3.1.1 |
Affected products
13- cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- Django/Djangodescription
- osv-coords6 versionspkg:bitnami/djangopkg:pypi/djangopkg:rpm/opensuse/python-Django&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django4&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django5&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django6&distro=openSUSE%20Tumbleweed
>= 2.2.0, < 2.2.16+ 5 more
- (no CPE)range: >= 2.2.0, < 2.2.16
- (no CPE)range: >= 2.2a1, < 2.2.16
- (no CPE)range: < 3.2.7-2.3
- (no CPE)range: < 4.2.14-1.1
- (no CPE)range: < 5.2.16-1.1
- (no CPE)range: < 6.0-1.1
Patches
Vulnerability mechanics
References
24- docs.djangoproject.com/en/dev/releases/security/nvdPatchVendor Advisory
- www.openwall.com/lists/oss-security/2020/09/01/2nvdMailing ListPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujan2021.htmlnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-m6gj-h9gm-gw44ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-24583ghsaADVISORY
- security.netapp.com/advisory/ntap-20200918-0004/nvdThird Party Advisory
- usn.ubuntu.com/4479-1/nvdThird Party Advisory
- www.djangoproject.com/weblog/2020/sep/01/security-releases/nvdVendor Advisory
- docs.djangoproject.com/en/dev/releases/securityghsaWEB
- github.com/django/django/commit/8d7271578d7b153435b40fe40236ebec43cbf1b9ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2020-33.yamlghsaWEB
- groups.google.com/forum/ghsaWEB
- groups.google.com/forum/ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/F2ZHO3GZCJMP3DDTXCNVFV6ED3W64NAUghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/OLGFFLMF3X6USMJD7V5F5P4K2WVUTO3TghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/ZCRPQCBTV3RZHKVZ6K6QOAANPRZQD3GIghsaWEB
- security.netapp.com/advisory/ntap-20200918-0004ghsaWEB
- usn.ubuntu.com/4479-1ghsaWEB
- www.djangoproject.com/weblog/2020/sep/01/security-releasesghsaWEB
- groups.google.com/forum/nvd
- groups.google.com/forum/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2ZHO3GZCJMP3DDTXCNVFV6ED3W64NAU/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OLGFFLMF3X6USMJD7V5F5P4K2WVUTO3T/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZCRPQCBTV3RZHKVZ6K6QOAANPRZQD3GI/nvd
News mentions
0No linked articles in our index yet.