Hacker News·4 min read·medium

CosmosEscape: Taking over Every Database in Azure Cosmos DB

U
uvuv
CosmosEscape: Taking over Every Database in Azure Cosmos DB
AI Summary

Wiz Research discovered a critical vulnerability called 'CosmosEscape' in Azure Cosmos DB that allowed unauthorized access to internal databases. The flaw involved the Gremlin API and could have been used to compromise sensitive data across Microsoft services.

Wiz Research uncovered CosmosEscape , a critical vulnerability in Azure’s flagship database service, Azure Cosmos DB, via its Gremlin API. The vulnerability could have been exploited to compromise every database in the service, including Microsoft's own internal databases - potentially enabling a cross-service attack.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness

Get the full story

Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.

Create free account

Already have an account? Sign in

CosmosEscape: Taking over Every Database in Azure Cosmos DB — Headlinne — headlinne