CVE-2024-43613

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
12/11/2024
Last modified:
07/01/2025

Description

Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:azure_database_for_postgresql_flexible_server:*:*:*:*:*:*:*:* 12.0 (including) 12.20 (excluding)
cpe:2.3:a:microsoft:azure_database_for_postgresql_flexible_server:*:*:*:*:*:*:*:* 13.0 (including) 13.16 (excluding)
cpe:2.3:a:microsoft:azure_database_for_postgresql_flexible_server:*:*:*:*:*:*:*:* 14.0 (including) 14.13 (excluding)
cpe:2.3:a:microsoft:azure_database_for_postgresql_flexible_server:*:*:*:*:*:*:*:* 15.0 (including) 15.8 (excluding)
cpe:2.3:a:microsoft:azure_database_for_postgresql_flexible_server:*:*:*:*:*:*:*:* 16.0 (including) 16.4 (excluding)


References to Advisories, Solutions, and Tools