Related Vulnerabilities: CVE-2020-24584  

An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.

Severity Medium

Remote Yes

Type Insufficient validation

Description

An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.

AVG-1217 python-django 3.1-1 3.1.1-1 Medium Fixed FS#67794

https://www.djangoproject.com/weblog/2020/sep/01/security-releases/
https://github.com/django/django/commit/2b099caa5923afa8cfb5f1e8c0d56b6e0e81915b