| |
Wiz Research discovered CosmosEscape, a critical vulnerability in Azure Cosmos DB's Gremlin API that could have allowed attackers to compromise every database in the service, including Microsoft's internal systems. The vulnerability exploited weaknesses in the Gremlin sandbox to enable attackers to retrieve a "Cosmos Master Key" granting full account takeover and the ability to enumerate all databases on the platform. Microsoft has fully remediated the issue and found no evidence of exploitation beyond the research itself.
Read Full Article →
← More Tech news