pid file is created as root before drops privileges and was susceptible
to a symlink attack -> could be used to overwrite arbitrary files on the
system
Incorrect handling of permissions on directories in caches - caused by a
behavioural change in python 3.7 - so only affects Python Django when
used with python 3.7 and hence say bionic (which uses python 3.6) is not
affected