PT-2025-23364 · Unknown · Django-Helpdesk

Published

2025-05-31

·

Updated

2025-06-16

·

CVE-2018-25111

CVSS v3.1

5.1

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions django-helpdesk versions prior to 1.0.0
Description The issue concerns Sensitive Data Exposure due to the use of os.umask(0) in models.py. This allows unauthorized access to sensitive information.
Recommendations For versions prior to 1.0.0, update to version 1.0.0 or later to resolve the issue. As a temporary workaround, consider modifying the os.umask(0) call in models.py to a more secure setting until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

CVE-2018-25111
GHSA-M4JX-M5HG-QRXX
PYSEC-2025-44

Affected Products

Django-Helpdesk