Microsoft Fixes CosmosEscape Flaw That Could Allow Any Cosmos DB Takeover
Microsoft has fixed a critical vulnerability in Azure Cosmos DB that could have allowed an attacker to locate and take control of databases belonging to any customer. Wiz Research named the flaw CosmosEscape and said it also placed databases used internally by Microsoft services within reach.
The vulnerability was found in the Gremlin API, an interface used to work with graph databases, where information is stored as connected items and relationships. A malicious user needed an Azure Cosmos DB account of their own, but did not need access to the organization they intended to target.
According to Wiz’s findings shared with Hackread.com, a specially prepared Gremlin query could break out of the restricted environment processing it and run commands on Microsoft’s backend systems. From there, the researchers obtained a platform secret they named the “Cosmos Master Key.”
TechnologyNews
Master Key Opened Two Paths to Customer Data
Possession of that...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE