CVE-2018-25111 Information

Description

django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py.

Reference

https://github.com/django-helpdesk/django-helpdesk/issues/591 https://github.com/django-helpdesk/django-helpdesk/pull/1120 https://github.com/django-helpdesk/django-helpdesk/releases/tag/v1.0.0

Share on: