CVE-2024-26164: Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability
Published Mar 12, 2024
·Updated
Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability
Affected Software
3 affected componentsFixes available
pip/mssql-django<1.4.1
1.4.1
Microsoft Django Backend Sql Server<1.4.1
Microsoft SQL Server backend for Django
Event History
Mar 12, 2024
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·04:57 PM
Data Sourced
via MITRE·04:57 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-26164?
CVE-2024-26164 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2024-26164?
To fix CVE-2024-26164, upgrade to version 1.4.1 of the mssql-django package.
3
Which software is affected by CVE-2024-26164?
CVE-2024-26164 affects the Microsoft SQL Server backend for Django.
4
Is there a patch available for CVE-2024-26164?
Yes, a patch is available in the form of an upgrade to version 1.4.1 of mssql-django.
5
What type of vulnerability is CVE-2024-26164?
CVE-2024-26164 is classified as a remote code execution vulnerability.