CVE-2020-24584
published 2020-09-01CVE-2020-24584: An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
3.27%
87.0th percentile
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | python-django | < python-django 2:2.2.16-1 (bookworm) | python-django 2:2.2.16-1 (bookworm) |
| djangoproject | django | >= 2.2 < 2.2.16 | 2.2.16 |
| djangoproject | django | >= 2.2 < 2.2.16 | 2.2.16 |
| djangoproject | django | >= 3.0 < 3.0.10 | 3.0.10 |
| djangoproject | django | >= 3.0 < 3.0.10 | 3.0.10 |
| djangoproject | django | >= 3.1 < 3.1.1 | 3.1.1 |
| djangoproject | django | >= 3.1 < 3.1.1 | 3.1.1 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Django Incorrect Default Permissions
ghsa·2021-03-18
CVE-2020-24584 [MEDIUM] CWE-276 Django Incorrect Default Permissions
Django Incorrect Default Permissions
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.
OSV
Django Incorrect Default Permissions
osv·2021-03-18
CVE-2020-24584 [MEDIUM] Django Incorrect Default Permissions
Django Incorrect Default Permissions
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.
OSV
CVE-2020-24584: An issue was discovered in Django 2
osv·2020-09-01·CVSS 7.5
CVE-2020-24584 [HIGH] CVE-2020-24584: An issue was discovered in Django 2
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.
Ubuntu
Django vulnerabilities
vendor_ubuntu·2020-09-01
CVE-2020-24583 Django vulnerabilities
Title: Django vulnerabilities
Summary: Several security issues were fixed in Django.
It was discovered that Django, when used with Python 3.7 or higher,
incorrectly handled directory permissions. A local attacker could possibly
use this issue to obtain sensitive information, or escalate permissions.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+
vendor_redhat·2020-09-01·CVSS 7.5
CVE-2020-24584 [HIGH] CWE-276 django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+
django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.
A flaw was found in django. The intermediate-level directories of the file system cache had the system's standard umask rather than `0o077` (no group or others permissions). The highest threat from this vulnerability is to data confidentiality.
Statement: This flaw can only be triggered in Django by using Python version 3.7 and newer. While the flawed package is shipped with the below Red Hat products, the flaw cannot be activated without manually updating P
Debian
CVE-2020-24584: python-django - An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 ...
vendor_debian·2020·CVSS 7.5
CVE-2020-24584 [HIGH] CVE-2020-24584: python-django - An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 ...
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.
Scope: local
bookworm: resolved (fixed in 2:2.2.16-1)
bullseye: resolved (fixed in 2:2.2.16-1)
forky: resolved (fixed in 2:2.2.16-1)
sid: resolved (fixed in 2:2.2.16-1)
trixie: resolved (fixed in 2:2.2.16-1)
Suricata
ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-3354 [HIGH] ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id INSERT
ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id INSERT"; flow:established,to_server; http.uri; content:"/ViewCat.php?"; nocase; content:"s_user_id="; nocase; content:"INSERT"; nocase; content:"INTO"; distance:0; nocase; reference:cve,CVE-2007-3354; reference:url,www.securityfocus.com/bid/24584; classtype:web-application-attack; sid:2006549; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_04_17, mitre_tactic_id TA00
Suricata
ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-3354 [HIGH] ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id ASCII
ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id ASCII"; flow:established,to_server; http.uri; content:"/ViewCat.php?"; nocase; content:"s_user_id="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-3354; reference:url,www.securityfocus.com/bid/24584; classtype:web-application-attack; sid:2006551; rev:10; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_04_17, mitre_tactic_id TA0
Suricata
ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-3354 [HIGH] ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id UPDATE
ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id UPDATE"; flow:established,to_server; http.uri; content:"/ViewCat.php?"; nocase; content:"s_user_id="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-3354; reference:url,www.securityfocus.com/bid/24584; classtype:web-application-attack; sid:2006552; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_04_17, mitre_tactic_id TA000
Suricata
ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-3354 [HIGH] ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id UNION SELECT
ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id UNION SELECT"; flow:established,to_server; http.uri; content:"/ViewCat.php?"; nocase; content:"s_user_id="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-3354; reference:url,www.securityfocus.com/bid/24584; classtype:web-application-attack; sid:2006548; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_04_17, mitre_t
Suricata
ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-3354 [HIGH] ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id DELETE
ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id DELETE"; flow:established,to_server; http.uri; content:"/ViewCat.php?"; nocase; content:"s_user_id="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-3354; reference:url,www.securityfocus.com/bid/24584; classtype:web-application-attack; sid:2006550; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_04_17, mitre_tactic_id TA00
Suricata
ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-3354 [HIGH] ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id SELECT
ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS NetClassifieds Premium Edition SQL Injection Attempt -- ViewCat.php s_user_id SELECT"; flow:established,to_server; http.uri; content:"/ViewCat.php?"; nocase; content:"s_user_id="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-3354; reference:url,www.securityfocus.com/bid/24584; classtype:web-application-attack; sid:2006547; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_04_17, mitre_tactic_id TA00
No public exploits indexed.
Bugzilla
CVE-2020-24584 django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+
bugzilla·2020-09-01·CVSS 7.5
CVE-2020-24584 [HIGH] CVE-2020-24584 django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+
CVE-2020-24584 django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+
On Python 3.7+, the intermediate-level directories of the file system cache had the system's standard umask rather than ``0o077`` (no group or others permissions).
Reference:
https://www.djangoproject.com/weblog/2020/sep/01/security-releases/
Discussion:
Created django:1.6/python-django tracking bugs for this issue:
Affects: fedora-all [bug 1874495]
Created python-django tracking bugs for this issue:
Affects: epel-all [bug 1874493]
Affects: fedora-all [bug 1874494]
Affects: openstack-rdo [bug 1874496]
---
Upstream fix:
https://github.com/django/django/commit/1853724acaf17ed7414d54c7d2b5563a25025a71
---
External References:
https://www.djangoproject.com/weblog/
Bugzilla
CVE-2020-24584 python-django: django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+ [openstack-rdo]
bugzilla·2020-09-01·CVSS 7.5
CVE-2020-24584 [HIGH] CVE-2020-24584 python-django: django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+ [openstack-rdo]
CVE-2020-24584 python-django: django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+ [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
f
Bugzilla
CVE-2020-24584 python-django: django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+ [fedora-all]
bugzilla·2020-09-01·CVSS 7.5
CVE-2020-24584 [HIGH] CVE-2020-24584 python-django: django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+ [fedora-all]
CVE-2020-24584 python-django: django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+ [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg
Bugzilla
CVE-2020-24584 python-django: django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+ [epel-all]
bugzilla·2020-09-01·CVSS 7.5
CVE-2020-24584 [HIGH] CVE-2020-24584 python-django: django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+ [epel-all]
CVE-2020-24584 python-django: django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+ [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg comm
Bugzilla
CVE-2020-24584 django:1.6/python-django: django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+ [fedora-all]
bugzilla·2020-09-01·CVSS 7.5
CVE-2020-24584 [HIGH] CVE-2020-24584 django:1.6/python-django: django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+ [fedora-all]
CVE-2020-24584 django:1.6/python-django: django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+ [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and
https://docs.djangoproject.com/en/dev/releases/security/https://groups.google.com/forum/#%21topic/django-announce/Gdqn58RqIDMhttps://groups.google.com/forum/#%21topic/django-announce/zFCMdgUnutUhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2ZHO3GZCJMP3DDTXCNVFV6ED3W64NAU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OLGFFLMF3X6USMJD7V5F5P4K2WVUTO3T/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZCRPQCBTV3RZHKVZ6K6QOAANPRZQD3GI/https://security.netapp.com/advisory/ntap-20200918-0004/https://usn.ubuntu.com/4479-1/https://www.djangoproject.com/weblog/2020/sep/01/security-releases/https://www.openwall.com/lists/oss-security/2020/09/01/2https://www.oracle.com/security-alerts/cpujan2021.htmlhttps://docs.djangoproject.com/en/dev/releases/security/https://groups.google.com/forum/#%21topic/django-announce/Gdqn58RqIDMhttps://groups.google.com/forum/#%21topic/django-announce/zFCMdgUnutUhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2ZHO3GZCJMP3DDTXCNVFV6ED3W64NAU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OLGFFLMF3X6USMJD7V5F5P4K2WVUTO3T/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZCRPQCBTV3RZHKVZ6K6QOAANPRZQD3GI/https://security.netapp.com/advisory/ntap-20200918-0004/https://usn.ubuntu.com/4479-1/https://www.djangoproject.com/weblog/2020/sep/01/security-releases/https://www.openwall.com/lists/oss-security/2020/09/01/2https://www.oracle.com/security-alerts/cpujan2021.html
2020-09-01
Published