Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

Read full story on The Hacker News
Share
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
AI disclosure

Summary

A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a

Original reporting

Open original source
Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.