Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
Overview
A recently patched vulnerability in Azure Cosmos DB, identified by researchers at Wiz and named CosmosEscape, posed a significant risk to users by potentially allowing attackers to bypass the service's Gremlin query sandbox. This flaw could have granted full read and write access to all databases across various customer accounts. The exploit began with a specially crafted query directed at a Gremlin database that the attacker controlled. This incident is particularly concerning as it underscores the possibility of extensive data exposure across multiple tenants, which could have had severe implications for organizations relying on Azure Cosmos DB for their data storage needs. Companies using this service should ensure they have applied the latest patches to safeguard their databases.
Key Takeaways
- Affected Systems: Azure Cosmos DB
- Action Required: Patches have been released; users should update their Azure Cosmos DB instances to the latest version.
- Timeline: Newly disclosed
Original Article Summary
A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a
Impact
Azure Cosmos DB
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Newly disclosed
Remediation
Patches have been released; users should update their Azure Cosmos DB instances to the latest version.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Exploit, Vulnerability.