Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Debian 10 DLA-3164-1 Critical: Django Permissions And Cache Threats

debian lts
Calendar Grey October 28, 2022
Dist Debian Esm H88
A series of vulnerabilities in Django has been rectified in this Debian LTS release to bolster the protection of web applications.
Multiple vulnerabilities were discovered in Django, a popular Python-based web development framework: * CVE-2020-24583: Fix incorrect permissions on intermediate-level

Summary

* CVE-2020-24583: Fix incorrect permissions on intermediate-level
directories on Python 3.7+. FILE_UPLOAD_DIRECTORY_PERMISSIONS mode
was not applied to intermediate-level directories created in the
process of uploading files and to intermediate-level collected
static directories when using the collectstatic management
command. You should review and manually fix permissions on
existing intermediate-level directories.

* CVE-2020-24584: Correct permission escalation vulnerability in
intermediate-level directories of the file system cache. On Python
3.7 and above, the intermediate-level directories of the file
system cache had the system's standard umask rather than 0o077 (no
group or others permissions).

* CVE-2021-3281: Fix a potential directory-traversal exploit via
archive.extract(). The django.utils.archive.extract() function,
used by startapp --template and startproject --template, allowed
directory traversal via an archive with absolute paths or relative

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: python-django
Version: 1:1.11.29-1+deb10u2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here