Microsoft has addressed a privilege escalation and remote code execution problem affecting its Azure Database for PostgreSQL Flexible Server that potentially could have led to unauthorised database access.
Dubbed “ExtraReplica” by security vendor Wiz which found the issue, a set of vulnerabilities meant attackers could have replicated and gained read access to other customers’ databases.
An attacker could exploit an elevated permissions bug in the Flexible Server authentication process to leverage an improperly anchored regular expression to bypass authentication, Microsoft said.
The “ExtraReplica” vulnerabilities, which affected all PostgreSQL Flexible Servers deployed with the public access networking option activated, did not allow access to client data.
The vulnerabilities did not affect instances deployed with the private access networking option or Single Server PostgreSQL databases.
Customers are not obliged to take any action because Microsoft stated that the issues were resolved in January and February of this year.
Wiz pointed out that public tenant isolation documentation is absent from the PostgreSQL Flexible Server, making it impossible for users to assess risk during service onboarding.
This problem isn’t exclusive to Azure, according to Wiz, who believes cloud providers should be more open about their isolation architecture, especially for critical applications like databases.


