Feeds.4Sysops
Critical Vulnerability in Azure Cosmos DB Exposed Databases Globally
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Wiz Research identified a critical vulnerability named CosmosEscape in Azure Cosmos DB via its Gremlin API. This flaw allowed attackers to access every database within the service, including Microsoft's internal databases, by exploiting the Cosmos Master Key. The attack method involved retrieving primary keys for full read and write access and enumerating databases using organization identifiers. Microsoft has confirmed that the vulnerability has been fully remediated by eliminating the Cosmos Master Key and implementing new security measures. An investigation revealed no evidence of exploitation beyond the research conducted. Cosmos DB is widely used across Microsoft services, raising concerns about potential data exposure. The vulnerability highlights risks associated with custom query engines in cloud services.
Key Points: • CosmosEscape allowed access to all databases in Azure Cosmos DB, including internal Microsoft databases. • The vulnerability was mitigated by removing the Cosmos Master Key and enhancing security protocols. • No evidence of exploitation was found beyond the research conducted by Wiz Research.