Related Vulnerabilities: CVE-2020-13254  

An information disclosure issue has been found in Django before 3.0.7, via malformed memcached keys. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage. In order to avoid this vulnerability, key validation is added to the memcached cache backends.

Severity Medium

Remote Yes

Type Information disclosure

Description

An information disclosure issue has been found in Django before 3.0.7, via malformed memcached keys. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage. In order to avoid this vulnerability, key validation is added to the memcached cache backends.

AVG-1176 python-django 3.0.6-2 Medium Vulnerable

https://github.com/django/django/commit/84b2da5552e100ae3294f564f6c862fef8d0e693