CVE-2020-24583: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 4% chance of exploitation in the next 30 days.

An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level directories created in the process of uploading files. It was also not applied to intermediate-level collected static directories when using the collectstatic management command.

Affected products

  • Canonical Ubuntu Linux: version 20.04 only
  • Djangoproject Django: from 2.2, before 2.2.16 (fixed in 2.2.16); from 3.0, before 3.0.10 (fixed in 3.0.10); from 3.1, before 3.1.1 (fixed in 3.1.1)
  • Fedoraproject Fedora: version 31 only; version 32 only; version 33 only
  • Oracle ZFS Storage Appliance Kit: version 8.8 only

Published 2020-09-01. Last modified 2026-06-17.