Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mjgh-79qc-68w3

Опубликовано: 03 мар. 2026
Источник: github
Github: Прошло ревью
CVSS3: 3.7

Описание

Django has a Race Condition vulnerability

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29.

Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread's temporary umask change affects other threads in multi-threaded environments.

Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 6.0, < 6.0.3

6.0.3

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 5.2, < 5.2.12

5.2.12

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 4.2, < 4.2.29

4.2.29

EPSS

Процентиль: 1%
0.0001
Низкий

3.7 Low

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 3.7
ubuntu
22 дня назад

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread's temporary `umask` change affects other threads in multi-threaded environments. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS3: 3.7
redhat
22 дня назад

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread's temporary `umask` change affects other threads in multi-threaded environments. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS3: 3.7
nvd
22 дня назад

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread's temporary `umask` change affects other threads in multi-threaded environments. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS3: 3.7
debian
22 дня назад

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4. ...

suse-cvrf
8 дней назад

Security update for python-Django

EPSS

Процентиль: 1%
0.0001
Низкий

3.7 Low

CVSS3

Дефекты

CWE-362