5.1
CVE-2018-25111
- EPSS 0.17%
- Veröffentlicht 31.05.2025 00:00:00
- Zuletzt bearbeitet 16.06.2025 16:25:41
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Django-helpdesk Project ≫ Django-helpdesk Version < 1.0.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.066 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.4 | 1.8 | 2.5 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
|
| cve@mitre.org | 5.1 | 2.5 | 2.5 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
CWE-277 Insecure Inherited Permissions
A product defines a set of insecure permissions that are inherited by objects that are created by the program.
https://github.com/django-helpdesk/django-helpdesk/pull/1120
https://github.com/django-helpdesk/django-helpdesk/releases/tag/v1.0.0
https://github.com/django-helpdesk/django-helpdesk/issues/591