Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mjgh-79qc-68w3

Опубликовано: 03 мар. 2026
Источник: github
Github: Прошло ревью
CVSS3: 3.7

Описание

Django has a Race Condition vulnerability

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29.

Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread's temporary umask change affects other threads in multi-threaded environments.

Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 6.0, < 6.0.3

6.0.3

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 5.2, < 5.2.12

5.2.12

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 4.2, < 4.2.29

4.2.29

EPSS

Процентиль: 27%
0.00341
Низкий

3.7 Low

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 3.7
ubuntu
5 месяцев назад

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread's temporary `umask` change affects other threads in multi-threaded environments. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS3: 3.7
redhat
5 месяцев назад

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread's temporary `umask` change affects other threads in multi-threaded environments. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS3: 3.7
nvd
5 месяцев назад

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread's temporary `umask` change affects other threads in multi-threaded environments. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS3: 3.7
debian
5 месяцев назад

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4. ...

suse-cvrf
5 месяцев назад

Security update for python-Django

EPSS

Процентиль: 27%
0.00341
Низкий

3.7 Low

CVSS3

Дефекты

CWE-362