CyberSecurity News
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
AI summary
A vulnerability in Azure Cosmos DB has been discovered and patched, which could have allowed an attacker to gain full read and write access to databases across different customer accounts. The exploit chain, known as CosmosEscape, started with a specially crafted query against a Gremlin database under the attacker's control. This could have enabled the attacker to escape the service's Gremlin query sandbox. The vulnerability could have been used to access any database on the platform. The issue was identified by Wiz, a security company. The exploit chain involved code execution on a specific part of the system.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

