Hacker News·4 min read·medium
CosmosEscape: Taking over Every Database in Azure Cosmos DB
U
uvuv
✦AI Summary
Wiz Research discovered a critical vulnerability called 'CosmosEscape' in Azure Cosmos DB that allowed unauthorized access to internal databases. The flaw involved the Gremlin API and could have been used to compromise sensitive data across Microsoft services.
Wiz Research uncovered CosmosEscape , a critical vulnerability in Azure’s flagship database service, Azure Cosmos DB, via its Gremlin API. The vulnerability could have been exploited to compromise every database in the service, including Microsoft's own internal databases - potentially enabling a cross-service attack.
technologybusiness
✦
Get the full story
Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.
Create free accountAlready have an account? Sign in