Security · 2h ago
Azure Cosmos DB Flaw Could Have Exposed All Customer Databases
A vulnerability in Azure Cosmos DB allowed attackers to escape the Gremlin query sandbox and gain full read/write access to any database across tenants. The flaw, dubbed CosmosEscape by Wiz, was triggered by a crafted query on an attacker-controlled Gremlin database. Microsoft has patched the issue, but the bug could have led to a massive data breach.
Meridian48 take
The bug's platform-wide scope underscores the risk of shared infrastructure in cloud databases, even with sandboxing.
Read the full reporting
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database →
The Hacker News
azure-cosmos-dbcloud-security