An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level directories created in the process of uploading files. It was also not applied to intermediate-level collected static directories when using the collectstatic management command.
2020-09-01T13:15:11.150
2024-11-21T05:15:03.120
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | djangoproject | django | < 2.2.16 | Yes |
Application | djangoproject | django | < 3.0.10 | Yes |
Application | djangoproject | django | < 3.1.1 | Yes |
Operating System | canonical | ubuntu_linux | 20.04 | Yes |
Operating System | fedoraproject | fedora | 31 | Yes |
Operating System | fedoraproject | fedora | 32 | Yes |
Operating System | fedoraproject | fedora | 33 | Yes |
Application | oracle | zfs_storage_appliance_kit | 8.8 | Yes |