[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2020-24584":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":131,"aliases":132,"duplicate_of":9,"upstream":136,"downstream":137,"duplicates":156,"related":157,"reserved_at":9,"published_at":162,"modified_at":163,"state":164,"summary":165,"references_raw":174,"kevs":313,"epss":314,"epss_history":317,"metrics":563,"affected":578},"CVE-2020-24584","An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-276","Incorrect Default Permissions","During installation, installed file permissions are set to allow anyone to modify those files.","weakness","Draft","Base","Medium",[20,68,127],{"id":21,"name":22,"techniques":23},"CAPEC-1","Accessing Functionality Not Properly Constrained by ACLs",[24],{"id":25,"name":26,"tactics":27,"countermeasures":43},"T1574.010","Services File Permissions Weakness",[28,31,34,37,40],{"id":29,"name":30},"TA0110","Persistence",{"id":32,"name":33},"TA0111","Privilege Escalation",{"id":35,"name":36},"TA0030","Defense Evasion",{"id":38,"name":39},"TA0005","Stealth",{"id":41,"name":42},"TA0104","Execution",[44,49,53,58,63],{"id":45,"name":46,"tactic":47},"D3-SWI","Software Inventory",{"name":48},"Model",{"id":50,"name":51,"tactic":52},"D3-AVE","Asset Vulnerability Enumeration",{"name":48},{"id":54,"name":55,"tactic":56},"D3-SBV","Service Binary Verification",{"name":57},"Detect",{"id":59,"name":60,"tactic":61},"D3-SU","Software Update",{"name":62},"Harden",{"id":64,"name":65,"tactic":66},"D3-RS","Restore Software",{"name":67},"Restore",{"id":69,"name":70,"techniques":71},"CAPEC-127","Directory Indexing",[72],{"id":73,"name":74,"tactics":75,"countermeasures":79},"T1083","File and Directory Discovery",[76],{"id":77,"name":78},"TA0102","Discovery",[80,84,88,93,98,102,106,111,115,119,123],{"id":81,"name":82,"tactic":83},"D3-FA","File Analysis",{"name":57},{"id":85,"name":86,"tactic":87},"D3-FIM","File Integrity Monitoring",{"name":57},{"id":89,"name":90,"tactic":91},"D3-FEV","File Eviction",{"name":92},"Evict",{"id":94,"name":95,"tactic":96},"D3-DF","Decoy File",{"name":97},"Deceive",{"id":99,"name":100,"tactic":101},"D3-FE","File Encryption",{"name":62},{"id":103,"name":104,"tactic":105},"D3-RF","Restore File",{"name":67},{"id":107,"name":108,"tactic":109},"D3-LFP","Local File Permissions",{"name":110},"Isolate",{"id":112,"name":113,"tactic":114},"D3-CF","Content Filtering",{"name":110},{"id":116,"name":117,"tactic":118},"D3-RFAM","Remote File Access Mediation",{"name":110},{"id":120,"name":121,"tactic":122},"D3-CQ","Content Quarantine",{"name":110},{"id":124,"name":125,"tactic":126},"D3-CM","Content Modification",{"name":110},{"id":128,"name":129,"techniques":130},"CAPEC-81","Web Server Logs Tampering",[],[],[133,134,135],"GHSA-fr28-569j-53c4","BIT-django-2020-24584","PYSEC-2020-34",[],[138,140,142,144,146,148,150,152,154],{"_key":139},"ALPINE-CVE-2020-24584",{"_key":141},"UBUNTU-CVE-2020-24584",{"_key":143},"USN-4479-1",{"_key":145},"OPENSUSE-SU-2024:11205-1",{"_key":147},"OPENSUSE-SU-2024:13887-1",{"_key":149},"OPENSUSE-SU-2024:14208-1",{"_key":151},"DLA-3164-1",{"_key":153},"OPENSUSE-SU-2026:10005-1",{"_key":155},"DEBIAN-CVE-2020-24584",[],[158,159,160,161],{"_key":145},{"_key":147},{"_key":149},{"_key":153},"2020-09-01T12:36:06.000Z","2024-08-04T15:19:08.642Z","Modified",{"cisa_kev":166,"cisa_ransomware":166,"cisa_vendor":9,"epss_severity":167,"epss_score":168,"severity":169,"severity_score":170,"severity_version":171,"severity_source":172,"severity_vector":173,"severity_status":164},false,"low",0.02755,"high",7.5,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",[175,184,190,195,199,203,208,212,216,221,226,232,236,240,244,248,252,256,260,264,268,272,276,280,284,288,293,297,301,305,309],{"url":176,"sources":177,"tags":180},"https://docs.djangoproject.com/en/dev/releases/security/",[178,172,179],"cve.org","osv_pypi",[181,182,183],"X Refsource MISC","Vendor Advisory","WEB",{"url":185,"sources":186,"tags":187},"https://usn.ubuntu.com/4479-1/",[178,172,179],[182,188,189,183],"X Refsource UBUNTU","Third Party Advisory",{"url":191,"sources":192,"tags":193},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2ZHO3GZCJMP3DDTXCNVFV6ED3W64NAU/",[178,172],[182,194],"X Refsource FEDORA",{"url":196,"sources":197,"tags":198},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZCRPQCBTV3RZHKVZ6K6QOAANPRZQD3GI/",[178,172],[182,194],{"url":200,"sources":201,"tags":202},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OLGFFLMF3X6USMJD7V5F5P4K2WVUTO3T/",[178,172],[182,194],{"url":204,"sources":205,"tags":206},"https://www.oracle.com/security-alerts/cpujan2021.html",[178,172,179],[181,207,189,183],"Patch",{"url":209,"sources":210,"tags":211},"https://groups.google.com/forum/#%21topic/django-announce/zFCMdgUnutU",[178,172],[181],{"url":213,"sources":214,"tags":215},"https://groups.google.com/forum/#%21topic/django-announce/Gdqn58RqIDM",[178,172],[181],{"url":217,"sources":218,"tags":219},"https://www.openwall.com/lists/oss-security/2020/09/01/2",[178,172,179],[181,220,207,189,183],"Mailing List",{"url":222,"sources":223,"tags":224},"https://www.djangoproject.com/weblog/2020/sep/01/security-releases/",[178,172,179],[181,182,225],"ARTICLE",{"url":227,"sources":228,"tags":229},"https://security.netapp.com/advisory/ntap-20200918-0004/",[178,172,179],[230,189,231],"X Refsource CONFIRM","Advisory",{"url":233,"sources":234,"tags":235},"https://nvd.nist.gov/vuln/detail/CVE-2020-24584",[179],[231],{"url":237,"sources":238,"tags":239},"https://github.com/django/django/commit/1853724acaf17ed7414d54c7d2b5563a25025a71",[179],[183],{"url":241,"sources":242,"tags":243},"https://github.com/django/django/commit/2b099caa5923afa8cfb5f1e8c0d56b6e0e81915b",[179],[183],{"url":245,"sources":246,"tags":247},"https://github.com/django/django/commit/a3aebfdc8153dc230686b6d2454ccd32ed4c9e6f",[179],[183],{"url":249,"sources":250,"tags":251},"https://github.com/django/django/commit/cdb367c92a0ba72ddc0cbd13ff42b0e6df709554",[179],[183],{"url":253,"sources":254,"tags":255},"https://www.djangoproject.com/weblog/2020/sep/01/security-releases",[179],[183],{"url":257,"sources":258,"tags":259},"https://usn.ubuntu.com/4479-1",[179],[183],{"url":261,"sources":262,"tags":263},"https://security.netapp.com/advisory/ntap-20200918-0004",[179],[183],{"url":265,"sources":266,"tags":267},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZCRPQCBTV3RZHKVZ6K6QOAANPRZQD3GI",[179],[183],{"url":269,"sources":270,"tags":271},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OLGFFLMF3X6USMJD7V5F5P4K2WVUTO3T",[179],[183],{"url":273,"sources":274,"tags":275},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F2ZHO3GZCJMP3DDTXCNVFV6ED3W64NAU",[179],[183],{"url":277,"sources":278,"tags":279},"https://groups.google.com/forum/#!topic/django-announce/zFCMdgUnutU",[179],[183],{"url":281,"sources":282,"tags":283},"https://groups.google.com/forum/#!topic/django-announce/Gdqn58RqIDM",[179],[183],{"url":285,"sources":286,"tags":287},"https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2020-34.yaml",[179],[183],{"url":289,"sources":290,"tags":291},"https://github.com/django/django",[179],[292],"PACKAGE",{"url":294,"sources":295,"tags":296},"https://github.com/advisories/GHSA-fr28-569j-53c4",[179],[231],{"url":298,"sources":299,"tags":300},"https://docs.djangoproject.com/en/dev/releases/security",[179],[183],{"url":302,"sources":303,"tags":304},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F2ZHO3GZCJMP3DDTXCNVFV6ED3W64NAU/",[179],[183],{"url":306,"sources":307,"tags":308},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZCRPQCBTV3RZHKVZ6K6QOAANPRZQD3GI/",[179],[183],{"url":310,"sources":311,"tags":312},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OLGFFLMF3X6USMJD7V5F5P4K2WVUTO3T/",[179],[183],[],{"date":315,"score":168,"percentile":316},"2026-06-04",0.86282,[318,322,325,328,331,334,337,340,342,345,348,351,354,357,360,363,365,367,370,372,375,378,380,382,384,386,389,392,395,398,400,403,406,409,412,415,417,420,423,426,428,430,433,436,439,442,444,447,450,453,456,459,462,465,469,472,474,477,480,483,486,489,491,494,497,499,502,504,507,509,512,514,516,518,521,524,527,530,532,534,536,539,542,544,547,550,552,555,557,560],{"date":319,"score":320,"percentile":321},"2025-11-04",0.0329,0.86695,{"date":323,"score":320,"percentile":324},"2025-11-05",0.86698,{"date":326,"score":320,"percentile":327},"2025-11-06",0.86694,{"date":329,"score":320,"percentile":330},"2025-11-07",0.86704,{"date":332,"score":320,"percentile":333},"2025-11-08",0.86708,{"date":335,"score":320,"percentile":336},"2025-11-09",0.86702,{"date":338,"score":320,"percentile":339},"2025-11-10",0.86701,{"date":341,"score":320,"percentile":333},"2025-11-11",{"date":343,"score":320,"percentile":344},"2025-11-12",0.86714,{"date":346,"score":320,"percentile":347},"2025-11-13",0.8672,{"date":349,"score":320,"percentile":350},"2025-11-14",0.86722,{"date":352,"score":320,"percentile":353},"2025-11-15",0.86716,{"date":355,"score":320,"percentile":356},"2025-11-16",0.86719,{"date":358,"score":320,"percentile":359},"2025-11-17",0.8671,{"date":361,"score":362,"percentile":356},"2025-11-18",0.0367,{"date":364,"score":362,"percentile":347},"2025-11-19",{"date":366,"score":362,"percentile":350},"2025-11-20",{"date":368,"score":320,"percentile":369},"2025-11-21",0.86724,{"date":371,"score":320,"percentile":356},"2025-11-22",{"date":373,"score":320,"percentile":374},"2025-11-23",0.86713,{"date":376,"score":320,"percentile":377},"2025-11-24",0.86712,{"date":379,"score":320,"percentile":377},"2025-11-25",{"date":381,"score":320,"percentile":377},"2025-11-26",{"date":383,"score":320,"percentile":374},"2025-11-27",{"date":385,"score":320,"percentile":324},"2025-11-28",{"date":387,"score":320,"percentile":388},"2025-11-29",0.86773,{"date":390,"score":320,"percentile":391},"2025-11-30",0.86772,{"date":393,"score":320,"percentile":394},"2025-12-01",0.86829,{"date":396,"score":320,"percentile":397},"2025-12-02",0.86831,{"date":399,"score":320,"percentile":394},"2025-12-03",{"date":401,"score":320,"percentile":402},"2025-12-04",0.86767,{"date":404,"score":320,"percentile":405},"2025-12-05",0.86769,{"date":407,"score":320,"percentile":408},"2025-12-06",0.86766,{"date":410,"score":320,"percentile":411},"2025-12-07",0.86758,{"date":413,"score":320,"percentile":414},"2025-12-08",0.86759,{"date":416,"score":320,"percentile":402},"2025-12-09",{"date":418,"score":320,"percentile":419},"2025-12-10",0.86787,{"date":421,"score":320,"percentile":422},"2025-12-11",0.86793,{"date":424,"score":320,"percentile":425},"2025-12-12",0.86796,{"date":427,"score":320,"percentile":422},"2025-12-13",{"date":429,"score":320,"percentile":419},"2025-12-14",{"date":431,"score":320,"percentile":432},"2025-12-15",0.86785,{"date":434,"score":320,"percentile":435},"2025-12-16",0.86792,{"date":437,"score":320,"percentile":438},"2025-12-17",0.86795,{"date":440,"score":320,"percentile":441},"2025-12-18",0.86804,{"date":443,"score":320,"percentile":441},"2025-12-19",{"date":445,"score":320,"percentile":446},"2025-12-20",0.86803,{"date":448,"score":320,"percentile":449},"2025-12-21",0.86805,{"date":451,"score":320,"percentile":452},"2025-12-22",0.868,{"date":454,"score":320,"percentile":455},"2025-12-23",0.86802,{"date":457,"score":320,"percentile":458},"2025-12-24",0.86812,{"date":460,"score":320,"percentile":461},"2025-12-25",0.86824,{"date":463,"score":320,"percentile":464},"2025-12-26",0.86825,{"date":466,"score":467,"percentile":468},"2025-12-27",0.02294,0.84343,{"date":470,"score":320,"percentile":471},"2025-12-28",0.8682,{"date":473,"score":320,"percentile":458},"2025-12-29",{"date":475,"score":320,"percentile":476},"2025-12-30",0.86816,{"date":478,"score":320,"percentile":479},"2025-12-31",0.86826,{"date":481,"score":320,"percentile":482},"2026-01-01",0.86884,{"date":484,"score":320,"percentile":485},"2026-01-02",0.86887,{"date":487,"score":320,"percentile":488},"2026-01-03",0.86888,{"date":490,"score":320,"percentile":461},"2026-01-04",{"date":492,"score":320,"percentile":493},"2026-01-05",0.86821,{"date":495,"score":320,"percentile":496},"2026-01-06",0.86823,{"date":498,"score":320,"percentile":464},"2026-01-07",{"date":500,"score":320,"percentile":501},"2026-01-08",0.86835,{"date":503,"score":320,"percentile":501},"2026-01-09",{"date":505,"score":320,"percentile":506},"2026-01-10",0.86837,{"date":508,"score":320,"percentile":397},"2026-01-11",{"date":510,"score":320,"percentile":511},"2026-01-12",0.86828,{"date":513,"score":320,"percentile":464},"2026-01-13",{"date":515,"score":320,"percentile":506},"2026-01-14",{"date":517,"score":320,"percentile":506},"2026-01-15",{"date":519,"score":320,"percentile":520},"2026-01-16",0.86843,{"date":522,"score":320,"percentile":523},"2026-01-17",0.86845,{"date":525,"score":320,"percentile":526},"2026-01-18",0.86847,{"date":528,"score":320,"percentile":529},"2026-01-19",0.86842,{"date":531,"score":320,"percentile":506},"2026-01-20",{"date":533,"score":320,"percentile":529},"2026-01-21",{"date":535,"score":320,"percentile":526},"2026-01-22",{"date":537,"score":320,"percentile":538},"2026-01-23",0.86862,{"date":540,"score":320,"percentile":541},"2026-01-24",0.86868,{"date":543,"score":320,"percentile":538},"2026-01-25",{"date":545,"score":320,"percentile":546},"2026-01-26",0.86858,{"date":548,"score":320,"percentile":549},"2026-01-27",0.8686,{"date":551,"score":320,"percentile":538},"2026-01-28",{"date":553,"score":320,"percentile":554},"2026-01-29",0.86864,{"date":556,"score":320,"percentile":554},"2026-01-30",{"date":558,"score":320,"percentile":559},"2026-01-31",0.86866,{"date":561,"score":320,"percentile":562},"2026-02-01",0.86932,[564,573],{"source":172,"cvss_v2_0":565,"cvss_v3_0":9,"cvss_v3_1":570,"cvss_v4_0":9},{"baseScore":566,"baseSeverity":9,"vectorString":567,"impactScore":568,"exploitabilityScore":569},5,"AV:N/AC:L/Au:N/C:P/I:N/A:N",2.9,10,{"baseScore":170,"baseSeverity":571,"vectorString":173,"impactScore":572,"exploitabilityScore":569},"HIGH",6,{"source":179,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":574,"cvss_v4_0":575},{"baseScore":170,"baseSeverity":9,"vectorString":173,"impactScore":572,"exploitabilityScore":569},{"baseScore":576,"baseSeverity":9,"vectorString":577,"impactScore":9,"exploitabilityScore":9},6.9,"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",[579,588,609,619,626],{"ecosystem":9,"name":580,"vendor":581,"product":582,"cpe_part":583,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":584},"ubuntu linux","canonical","ubuntu_linux","o",[585],{"version":586,"is_range":166,"range_type":587,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"20.04","cpe",{"ecosystem":9,"name":589,"vendor":590,"product":591,"cpe_part":592,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":593},"Django","djangoproject","django","a",[594,601,605],{"version":595,"is_range":596,"range_type":587,"version_start":597,"version_start_type":598,"version_end":599,"version_end_type":600,"fixed_in":9},"gte2.2_lt2.2.16",true,"2.2","including","2.2.16","excluding",{"version":602,"is_range":596,"range_type":587,"version_start":603,"version_start_type":598,"version_end":604,"version_end_type":600,"fixed_in":9},"gte3.0_lt3.0.10","3.0","3.0.10",{"version":606,"is_range":596,"range_type":587,"version_start":607,"version_start_type":598,"version_end":608,"version_end_type":600,"fixed_in":9},"gte3.1_lt3.1.1","3.1","3.1.1",{"ecosystem":9,"name":610,"vendor":611,"product":610,"cpe_part":583,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":612},"fedora","fedoraproject",[613,615,617],{"version":614,"is_range":166,"range_type":587,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"31",{"version":616,"is_range":166,"range_type":587,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"32",{"version":618,"is_range":166,"range_type":587,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"33",{"ecosystem":9,"name":620,"vendor":621,"product":622,"cpe_part":592,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":623},"zfs storage appliance kit","oracle","zfs_storage_appliance_kit",[624],{"version":625,"is_range":166,"range_type":587,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"8.8",{"ecosystem":627,"name":591,"vendor":627,"product":591,"cpe_part":9,"purl_type":628,"purl_namespace":9,"purl_name":591,"source":9,"versions":629},"PyPI","pypi",[630,633,635],{"version":631,"is_range":596,"range_type":632,"version_start":597,"version_start_type":598,"version_end":599,"version_end_type":600,"fixed_in":9},"gte2_2_lt2_2_16","ecosystem",{"version":634,"is_range":596,"range_type":632,"version_start":603,"version_start_type":598,"version_end":604,"version_end_type":600,"fixed_in":9},"gte3_0_lt3_0_10",{"version":636,"is_range":596,"range_type":632,"version_start":607,"version_start_type":598,"version_end":608,"version_end_type":600,"fixed_in":9},"gte3_1_lt3_1_1"]