Wiz Research discovers "ExtraReplica"— a cross-account database vulnerability in Azure PostgreSQL
ID: 4850aa65-5ae0-5b74-aa32-45e314e3ca80
STIX ID: report--4850aa65-5ae0-5b74-aa32-45e314e3ca80
Feed Name: Wiz Blog
Wiz Research disclosed "ExtraReplica", a chain of critical flaws in Azure Database for PostgreSQL Flexible Server that let an attacker escalate privileges on an attacker-controlled instance and then abuse an overly permissive certificate Common Name validation to impersonate the replication user and replicate/read other tenants' databases; Microsoft was notified, issued fixes, and reported no known exploitation, but publicly accessible Flexible Server instances (non-VNet) were potentially vulnerable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
