CVE-2024-39330: Django CVE-2024-38875, CVE-2024-39329, CVE-2024-39330, and CVE-2024-39614

Published Jul 5, 2024
·
Updated

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. Derived classes of the django.core.files.storage.Storage base class, when they override generatefilename() without replicating the file-path validations from the parent class, potentially allow directory traversal via certain inputs during a save() call. (Built-in Storage sub-classes are unaffected.)

Other sources

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. Derived classes of the django.core.files.storage.Storage base class, when they override generatefilename() without replicating the file-path validations from the parent class, potentially allow directory traversal via certain inputs during a save() call. (Built-in Storage sub-classes are unaffected.)

NVD

Derived classes of the django.core.files.storage.Storage base class which override generatefilename() without replicating the file path validations existing in the parent class, allow for potential directory-traversal via certain inputs when calling save(). Built-in Storage sub-classes were not affected by this vulnerability.

Affected versions =================

Django main development branch Django 5.1 Django 5.0 Django 4.2

Red Hat

Django could allow a remote attacker to traverse directories on the system, caused by improper validation of user request. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

IBM

Affected Software

6 affected componentsFixes available
pip/Django>=4.2<4.2.14
4.2.14
pip/Django>=5.0<5.0.7
5.0.7
debian/python-django<=2:2.2.28-1~deb11u2, <=3:3.2.19-1+deb12u1
3:4.2.16-1
IBM Storage Defender - Resiliency Service<=2.0.0 - 2.0.9
djangoproject Django>=4.2<4.2.14
djangoproject Django>=5.0<5.0.7

Event History

Jul 5, 2024
Data Sourced
via Red Hat·09:58 AM
DescriptionSeverityAffected Software
Jul 10, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
Description
Data Sourced
via NVD·05:15 AM
SeverityWeaknessAffected Software
Advisory Published
via GitHub·06:33 AM
Sep 15, 2024
Data Sourced
via Ubuntu·07:46 PM
RemedyDescriptionSeverityAffected Software
Dec 18, 2024
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-39330?

CVE-2024-39330 is classified as a high-severity vulnerability due to potential file path exposures in Django.

2

How do I fix CVE-2024-39330?

To fix CVE-2024-39330, upgrade to Django version 5.0.7, 4.2.14, or apply the appropriate patches if using a derivative package.

3

Which versions are affected by CVE-2024-39330?

CVE-2024-39330 affects Django versions prior to 5.0.7 and 4.2 prior to 4.2.14.

4

What impact does CVE-2024-39330 have on my application?

CVE-2024-39330 may allow attackers to manipulate file paths, potentially leading to security risks such as unauthorized file access.

5

Is there a mitigation if I cannot upgrade for CVE-2024-39330?

If unable to upgrade, ensure that any overridden `generate_filename()` methods replicate the file-path validations from the parent class.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203