Story thread · 5 reports / 5 sources

Microsoft almost gave away the keys to everyone’s Azure Cosmos DBs

infoworld.com · 11d

Microsoft almost gave away the keys to everyone’s Azure Cosmos DBs

How the coverage leans

Across 5 sources · syndicated copies counted once

Microsoft has had a narrow escape from total embarrassment: A security company uncovered a critical vulnerability that could have compromised all Azure Cosmos DB databases — both those of customers and Microsoft’s own. Google subsidiary Wiz found a flaw in the database’s Gremlin API, usually used for storing and managing property graph data. If bad actors had discovered it first, they could have exploited it to acquire what Wiz called the Cosmos Master Key, which would have enabled them to use the primary key of any Cosmos database, resulting in read and write access to any account. They would also have had access to a list of every database on the service, with identifiers such as subscription and tenant IDs. Azure Cosmos DB is a NoSQL database that underpins Microsoft’s cloud services. It can be accessed through SDKs for framework such as Python, Node.js, Java, and .NET. Wiz described how it discovered the vulnerability in a blog post. It disclosed details of the flaw to Microsoft in

First report: Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database thehackernews.com, 12d

The coverage

  1. CosmosEscape allowed the takeover of all Microsoft Azure databases

    heise.de · 11d

  2. Critical Flaw Led to Azure Cosmos DB Pwnage

    securityweek.com · 11d

The conversation · 0

Sign in to join the conversation.

No comments yet — start the thread.